t-mobile[.]lvdcf[.]cc
t-mobile.lvdcf.cc — Контент недоступен (HTTP 502). Олицетворение бренда: Genericcloudflare. Сводка доказательств: VirusTotal 12/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Forcepoint ThreatSeeker); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 86/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
t-mobile.lvdcf.cc was registered on 21 February 2026. Within weeks it appeared on a security blocklist and was subsequently taken offline, as indicated by the PhishDestroy block. DNS resolution points to 172.67.200.144, an address owned by Cloudflare, Inc. (AS13335) located in the United States. The domain’s TLS certificate, identified as WE1, was observed in the initial scan.
VirusTotal analysis recorded 12 detections out of 93 scanned scanners, confirming that multiple security products consider the domain malicious. The limited blocklist presence (one listing) and the offline HTTP status suggest that the phishing infrastructure was short‑lived, possibly used for a targeted campaign and then abandoned. No public page title, brand targeting, or kit identification has been released, so the exact phishing template and victim lure remain unknown.
Given the recent creation date, the association with Cloudflare’s edge network, and the confirmed detections, defenders should add the domain and its resolved IP to outbound and inbound filtering rules, cite the VirusTotal detection count in automated blocking policies, and monitor for any re‑registration of the same second‑level domain or similar sub‑domains. Continuous enrichment of threat‑intel feeds for new listings of t-mobile.lvdcf.cc or related C‑NAMEs is recommended. Until further evidence surfaces, the domain should be treated as a confirmed phishing indicator with elevated risk.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание