t-mobile[.]sbyue[.]cc
“Welcome to nginx!”
t-mobile.sbyue.cc — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 13/93 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); PhishDestroy score 89/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain t-mobile.sbyue.cc was registered on February 21, 2026 through Gname.com Pte. Ltd. and is currently flagged as a brand impersonation targeting x.com. DNS resolution points to the IPv6 address 2606:4700:3032::ac43:8ce2, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The authoritative nameservers are bristol.ns.cloudflare.com and quentin.ns.cloudflare.com, confirming the use of Cloudflare's DNS infrastructure. An HTTP request returns the default page title "Welcome to nginx!" and no SSL certificate is presented, indicating an unencrypted service. The site was assessed by VirusTotal, where 13 of 93 security vendors reported the domain as malicious.
Independent analysis assigns a Gridinsoft trust score of 0 out of 100, reflecting a lack of trustworthiness. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy remediation service. Its operational status is listed as offline, but the presence of the domain in multiple detection mechanisms suggests that the infrastructure may be reused or reactivated. Defenders should add t-mobile.sbyue.cc to network deny lists, enforce DNS sinkholing for the associated IPv6 address, and ensure that any email or web traffic claiming to originate from x.com is scrutinized.
Continuous monitoring of the Cloudflare IP range for similar impersonation attempts is advised, as the hosting provider can host a large volume of unrelated legitimate services. Organizations should also update endpoint protection signatures to incorporate the 13 vendor detections reported by VirusTotal, and verify that any internal reference to the domain is blocked at the firewall or proxy level. Because the site lacks an SSL certificate, interception of clear‑text traffic can be used for further intelligence gathering if the domain reappears. Maintaining awareness of the registrar Gname.com Pte. Ltd. may aid in future attribution efforts.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260122-45144E Recipient: complaint@gname.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание