t-mobile[.]smbfw[.]cc
“Welcome to nginx!”
t-mobile.smbfw.cc — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, Cluster25); URLQuery 4 alerts; PhishDestroy score 95/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, t-mobile.smbfw.cc, is flagged as a brand impersonation threat designed to deceive users by mimicking T-Mobile, a major telecommunications provider. Analysis indicates the site was structured to exploit brand recognition, likely for credential theft or fraudulent transactions. No crypto drainer kit signatures were detected, but the domain’s infrastructure aligns with known impersonation tactics targeting consumer trust. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 172.67.138.136, hosted on Cloudflare’s network (AS13335). It was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. VirusTotal reports 18 out of 95 security vendors flagging the domain, while it appears on one security blocklist. The absence of an SSL certificate and the default nginx welcome page suggest minimal effort to mask malicious intent, a common trait in short-lived impersonation campaigns. The domain is currently offline, having been taken down following detection by security systems. However, residual risk remains due to the registrar’s history of hosting fraudulent domains and the potential for re-registration under a similar name. Users who interacted with this domain should monitor accounts for unauthorized activity and verify communications through official T-Mobile channels. Organizations are advised to block the domain and IP at the network level to prevent accidental exposure.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | t-mobile.smbfw.cc |
malicious | Sinkholed |
| OpenDNS | t-mobile.smbfw.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.smbfw.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.smbfw.cc |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
PD-20260125-776137 Recipient: complaint@gname.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.