t-mobile[.]zfeor[.]cc
“zfeor.cc | 522: Connection timed out”
t-mobile.zfeor.cc — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: T-mobile. Ringkasan bukti: VirusTotal 13/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Emsisoft); URLQuery 4 alerts; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 93/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of t-mobile.zfeor.cc shows a brand‑impersonation infrastructure that was active during early 2026. The domain was registered on February 21 2026 via Gname.com Pte. Ltd. and is hosted on Cloudflare’s network (ASN 13335) in the United States, resolving to 104.21.77.181. DNS resolution points to the Cloudflare authoritative nameservers matias.ns.cloudflare.com and paige.ns.cloudflare.com, and the site served over HTTP/3, indicating a modern CDN configuration. The TLS certificate presented is issued by Google Trust Services under the WE1 root, confirming a valid HTTPS endpoint despite the site returning a 522 “Connection timed out” page title.
Security‑vendor scanning on VirusTotal recorded 13 positive detections out of 93 scanners, and the domain is listed on a single external blocklist. Independent threat‑intel feeds (PhishDestroy) have already taken the site offline, and the Gridinsoft trust score is 0 / 100, reflecting an extremely low reputation. The observed phishing kit is labeled “Airdrop Scam,” and the domain explicitly impersonates the t‑mobile brand.
No additional content was captured, so the exact payload or credential‑harvesting pages remain unknown. Defenders should immediately block the IPv4 address 104.21.77.181 and the domain t-mobile.zfeor.cc at perimeter and endpoint layers, enforce URL filtering for Cloudflare‑hosted domains that resolve to the same ASN, and monitor for any re‑registration attempts. Continued observation of the associated nameservers and certificate fingerprint is advised to detect potential re‑use of the infrastructure for new impersonation campaigns.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.zfeor.cc |
phishing | Phishing Block |
| Cloudflare DNS | t-mobile.zfeor.cc |
malicious | Sinkholed |
| DNS4EU | t-mobile.zfeor.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.zfeor.cc |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
PD-20260202-43FBCF Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive