t-mobile[.]zbkay[.]cc
“zbkay.cc | 522: Connection timed out”
t-mobile.zbkay.cc — Non vérifié. Usurpation de l'identité de la marque : Genericcloudflare; Type d'arnaque : Impersonation. Résumé des preuves: VirusTotal 14/91 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 92/100. Bureau d’enregistrement: Gname.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, t-mobile.zbkay.cc, is actively flagged as a high-risk phishing site targeting the T-Mobile brand. Analysis indicates the subdomain was registered under zbkay.cc on February 21, 2026, and remains operational as of July 12, 2026. The domain resolves to IP address 188.114.96.3, hosted on Cloudflare’s infrastructure (AS13335), which is commonly used to obscure malicious activity behind legitimate content delivery networks. Security vendors have detected this domain, with 16 out of 95 engines on VirusTotal identifying it as malicious, while it also appears on one security blocklist. Infrastructure review reveals the domain employs Cloudflare nameservers (autumn.ns.cloudflare.com and yadiel.ns.cloudflare.com) and an SSL certificate issued by Google Trust Services (WE1). The HTTP status code returned is 200, though the page title displays a Cloudflare 522 timeout error, suggesting either intermittent availability or deliberate evasion of automated analysis. The use of HTTP/3 further aligns with modern phishing tactics to improve performance and bypass legacy security controls. While the exact content of the phishing page remains unconfirmed due to the timeout error, the subdomain structure (t-mobile.zbkay.cc) strongly implies an attempt to impersonate T-Mobile for credential harvesting or fraudulent transactions. Defenders should treat this domain as active and high-risk, blocking resolution at the DNS level and monitoring for connections to 188.114.96.3. Given the domain’s recent creation and Cloudflare-backed infrastructure, additional subdomains or IP rotations may emerge, warranting continuous monitoring of related indicators.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif