t-mobile[.]btlkx[.]cc
“Welcome to nginx!”
t-mobile.btlkx.cc — 콘텐츠를 사용할 수 없음 (HTTP 502). 증거 요약: VirusTotal 17/93 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, Cluster25); URLQuery 1 alert; PhishDestroy score 95/100. 등록기관: Gname.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, t-mobile.btlkx.cc, is identified as a brand impersonation threat specifically targeting users of X.com (formerly Twitter). The site presents a fraudulent login interface designed to harvest user credentials, including usernames, passwords, and potentially multifactor authentication codes. Analysis of the domain's infrastructure and behavior indicates it is part of a credential phishing campaign aimed at compromising social media accounts for further malicious activities, such as spreading disinformation, conducting financial fraud, or launching secondary phishing attacks against contacts. Evidence supporting this assessment includes multiple technical indicators. The domain was registered on January 22, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with suspicious domains. VirusTotal reports that 17 out of 95 security vendors have flagged t-mobile.btlkx.cc as malicious, with detections ranging from phishing to brand impersonation. The domain resolves to IP address 172.67.131.9, hosted on Cloudflare's network (AS13335), which is commonly used to obfuscate the true origin of malicious infrastructure. Additionally, the domain lacks an SSL certificate, increasing the risk of interception during credential transmission. It appears on one security blocklist, and the page title 'Welcome to nginx!' suggests a default server configuration, often indicative of hastily deployed phishing kits. Users who have visited t-mobile.btlkx.cc or entered credentials on this domain should take immediate action to mitigate potential compromise. First, change the password for the affected X.com account and any other platforms where the same credentials may have been reused. Enable multifactor authentication if not already active, using an authenticator app rather than SMS-based methods. Monitor the account for unauthorized activity, such as posts, messages, or connected applications that were not authorized. If financial or sensitive personal information was entered, consider placing a fraud alert on credit files and reviewing account statements for suspicious transactions. Organizations should update their email and web filtering rules to block this domain and its associated IP address, and security teams should investigate any internal systems that may have interacted with the domain for signs of compromise.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.btlkx.cc |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
증거 및 외부 보고서
PD-20260124-C65AF1 Recipient: complaint@gname.com 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.