t-mobile[.]ljouf[.]cc
“T-Mobile Tuesdays - Get Free Stuff & Great Deals | T-Mobile”
t-mobile.ljouf.cc — Контент недоступен (HTTP 502). Олицетворение бренда: Apple; Тип мошенничества: Tech Support Scam. Сводка доказательств: VirusTotal 16/95 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain t-mobile.ljouf.cc was registered on January 12, 2026 through Gname.com Pte. Ltd. and is currently listed as offline. Technical analysis shows it resolves to the IP address 172.67.185.154, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The domain uses the nameservers A.SHARE-DNS.COM and B.SHARE-DNS.NET and presents an SSL certificate labelled WE1.
The page title returned from the web server is "T-Mobile Tuesdays - Get Free Stuff & Great Deals | T-Mobile," yet the intelligence categorises the activity as a tech support scam that impersonates Apple, indicating a brand‑impersonation vector. Reputation services assign a trust score of 0/100 on both Scamadviser and Gridinsoft, reflecting a complete lack of credibility. The domain appears on a single security blocklist, specifically PhishDestroy, and VirusTotal records show that 16 of 95 scanning vendors flagged the host as malicious, reinforcing the suspicion of abusive use.
Although the site is presently taken offline, the combination of a low trust score, presence on a phishing blocklist, multiple vendor detections, and the mismatched page title strongly suggests that the domain was intended to lure victims by masquerading as a legitimate Apple‑related tech support interaction. Defenders should continue to block the domain at network perimeter controls, monitor the associated IP range for any reactivation, and incorporate the indicator set—domain name, IP address, nameservers, and SSL fingerprint—into threat‑intel feeds. Further investigation is warranted to determine whether additional infrastructure shares the same hosting environment, but based on the available evidence the domain poses an elevated risk and should be treated as hostile.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание