t-mobile[.]btfhks[.]top
“Welcome to OpenResty!”
t-mobile.btfhks.top — Контент недоступен. Сводка доказательств: VirusTotal 12/91 (alphaMountain.ai, BitDefender, ESET, Emsisoft, Fortinet); URLQuery 1 alert; PhishDestroy score 88/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain t-mobile.btfhks.top was registered on 2026-06-01 through NameSilo, LLC and is currently using Cloudflare name servers burt.ns.cloudflare.com and michelle.ns.cloudflare.com. The domain resolves to the IPv4 address 188.114.96.3 and remains active as of the 2026-07-13 assessment. The operational profile matches a recently created infrastructure commonly observed in generic phishing campaigns, and the threat classification has been set to generic_phishing with a risk level of under_investigation. No public content, page title, or additional payload information has been disclosed, leaving the exact lure and credential‑harvesting mechanisms unknown. The short lifespan, use of reputable DNS provider, and immediate activation suggest an intent to exploit the freshness of the domain before detection. Defenders should consider adding the domain to block lists, enforce DNS filtering for outbound queries to the IP, and monitor for any authentication attempts that reference the domain. Ongoing observation is recommended to capture any future host or payload changes that could clarify the phishing vector.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | t-mobile.btfhks.top |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: btfhks.top
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain btfhks.top behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260713-315ED2 Recipient: abuse@nic.top Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание