t-mobile[.]knreb[.]cc
“knreb.cc | 522: Connection timed out”
t-mobile.knreb.cc — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: T-mobile; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 13/93 (ADMINUSLabs, Criminal IP, Cluster25, CRDF, CyRadar); PhishDestroy score 89/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of the domain t-mobile.knreb.cc indicates it is a brand impersonation scam targeting T-Mobile customers, classified as an elevated-risk threat. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd. and is currently offline, returning a 522 connection timeout error with the page title 'knreb.cc | 522: Connection timed out.' Infrastructure analysis reveals the domain uses Cloudflare nameservers (paityn.ns.cloudflare.com and syeef.ns.cloudflare.com) and resolves to the IP address 172.67.204.48, hosted on Cloudflare's network (AS13335) in the United States. No SSL certificate is present, increasing the risk of unencrypted communications.
Security vendor detections are notable: 13 of 93 engines on VirusTotal flagged the domain as malicious, and it appears on at least one security blocklist, including PhishDestroy. The domain is linked to an 'Airdrop Scam' phishing kit, a tactic commonly used to deceive users into divulging personal or financial information under the guise of a promotional giveaway. Gridinsoft assigns a trust score of 0/100, further corroborating its malicious classification.
While the domain is currently offline, defenders should treat it as a confirmed threat due to its infrastructure, detection history, and association with a known phishing kit. Organizations are advised to block the domain at the DNS or proxy level, monitor for related subdomains or IPs, and alert users to the risks of interacting with unsolicited T-Mobile-themed promotions. The exact content of the site is not yet analyzed, but the available evidence strongly supports its classification as a brand impersonation scam.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260118-2DCD44 Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive