t-mobile[.]fenrd[.]cc
“Welcome to nginx!”
t-mobile.fenrd.cc — Conteúdo indisponível (HTTP 502). Resumo das evidências: VirusTotal 17/95 (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); URLQuery 2 alerts; PhishDestroy score 95/100. Registrador: Gname.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain t-mobile.fenrd.cc indicates it was actively involved in brand impersonation targeting X.com, as documented in threat intelligence records from July 2026. The domain, registered on February 21, 2026, through Gname.com Pte. Ltd., resolved to the IP address 104.21.31.62, which is hosted on Cloudflare's infrastructure (AS13335) in the United States. At the time of assessment, the domain was offline, with no SSL certificate detected and an HTTP response displaying the default 'Welcome to nginx!' page title, suggesting either misconfiguration or an incomplete deployment of phishing infrastructure. Detection metrics reveal limited but clear indicators of malicious activity. The domain appeared on one security blocklist and was flagged by PhishDestroy.
VirusTotal records show that 17 out of 95 security vendors classified the domain as malicious, though the specific nature of the detections—whether related to phishing, malware, or other abuse—remains unconfirmed. The Gridinsoft trust score of 0/100 further corroborates its high-risk classification. Nameservers carlane.ns.cloudflare.com and trey.ns.cloudflare.com, also operated by Cloudflare, were associated with the domain, a common pattern in phishing campaigns leveraging Cloudflare's proxy services to obscure origin servers. The scam type is explicitly categorized as brand impersonation, with X.com identified as the targeted brand. While the domain is no longer active, its infrastructure and detection history align with known phishing tactics.
Defenders are advised to monitor for residual DNS records, subdomains, or related infrastructure that may resurface under different names. Organizations should update blocklists to include this domain and investigate any prior connections from internal networks. Given the use of Cloudflare, additional scrutiny of domains sharing the same nameservers or IP ranges may uncover related malicious activity.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.fenrd.cc |
phishing | Phishing Block |
| Hagezi Threat Feed | t-mobile.fenrd.cc |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
PD-20260118-EFCA9C Recipient: complaint@gname.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo