t-mobile[.]ojre[.]cc
“Welcome to nginx!”
t-mobile.ojre.cc — Contenuto non disponibile (HTTP 502). Riepilogo delle prove: VirusTotal 11/95 (Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 83/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of the domain t-mobile.ojre.cc indicates that it is currently taken offline but retains a number of malicious indicators. The domain was registered on February 21, 2026 through Gname.com Pte. Ltd. and is hosted on Cloudflare infrastructure, resolving to IP address 104.21.75.136, which belongs to AS13335 Cloudflare, Inc. in the United States. The authoritative nameservers are rachel.ns.cloudflare.com and yew.ns.cloudflare.com, confirming the use of Cloudflare's DNS services. No SSL certificate is presented for the site, and the HTTP response contains the generic page title "Welcome to nginx!", suggesting a default web server configuration rather than a crafted phishing page. The registrar and hosting details, combined with the lack of TLS, are typical of fast‑flux or temporary phishing deployments.
Threat intelligence flags the domain as a brand impersonation targeting x.com. The scam type is explicitly listed as "Brand Impersonation" and the domain appears on at least one security blocklist, specifically PhishDestroy, which has already blocked the host. A reputation assessment by Gridinsoft assigns a trust score of 0 out of 100, indicating the highest level of suspicion. VirusTotal has recorded 11 detections out of 95 scanners, reinforcing the malicious classification.
While the site is offline, the existing artifacts provide sufficient evidence for defensive teams to enact preventive controls. Organizations should add t-mobile.ojre.cc to URL filtering and DNS blocklists, monitor for any future resolution to the same IP range, and enforce TLS inspection policies to capture any potential re‑appearance of the domain under a new certificate. Continuous watch of the Cloudflare IP block for anomalous traffic patterns is advisable, as threat actors often reuse the same hosting provider for related campaigns.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260203-177642 Recipient: complaint@gname.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo