t-mobile[.]govk[.]cc
“Welcome to nginx!”
t-mobile.govk.cc — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 18/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain is flagged as an elevated-risk brand impersonation threat designed to deceive users of x.com. Analysis indicates the infrastructure was specifically engineered to mimic legitimate services while facilitating unauthorized access or data collection, a common tactic in credential harvesting campaigns. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain t-mobile.govk.cc, registered through Gname.com Pte. Ltd. on February 21, 2026, currently resolves to IP 47.86.49.23 (AS45102, Alibaba (US) Technology Co., Ltd., Hong Kong). It lacks SSL certification and displays the default nginx welcome page, suggesting either incomplete deployment or deliberate obfuscation. Security vendors flagged the domain in 18 of 95 VirusTotal scans, while PhishDestroy and one additional blocklist have implemented active protections. The creation date discrepancy (2026) further indicates suspicious registration practices, likely an attempt to bypass temporal-based detection systems. Mitigation requires immediate action from both organizational and individual stakeholders. Network administrators should implement DNS-level blocking for t-mobile.govk.cc and its resolving IP 47.86.49.23, while monitoring for related subdomains or IP adjacencies within the same ASN. Security teams should prioritize user education on brand impersonation tactics, particularly domains combining mobile service terminology with unrelated TLDs. End users should verify domain authenticity through official channels before interaction, especially when encountering unexpected login prompts or account verification requests. Continuous monitoring of certificate transparency logs and passive DNS records is recommended to detect potential re-emergence of this threat infrastructure.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.govk.cc |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260205-EB55FB Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive