t-mobile[.]yanzx[.]cc
t-mobile.yanzx.cc — Контент недоступен (HTTP 502). Олицетворение бренда: Genericcloudflare. Сводка доказательств: VirusTotal 17/95 (ADMINUSLabs, Chong Lua Dao, Cluster25, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 95/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, t-mobile.yanzx.cc, operates as a fake T-Mobile login portal designed to harvest user credentials. Victims are tricked into entering their usernames and passwords on a spoofed T-Mobile webpage, which then transmits the stolen data to threat actors. Such attacks are commonly used to gain unauthorized access to personal accounts, conduct identity theft, or facilitate further fraudulent activities like SIM swapping or unauthorized transactions. The site mimics legitimate T-Mobile branding to deceive users into believing they are interacting with an official service. Analysis indicates this domain is part of a phishing infrastructure with multiple technical red flags. The domain was registered on February 21, 2026, through Alibaba Cloud’s registrar, an entity frequently abused for malicious registrations. It is currently hosted on Cloudflare’s network (IP: 104.21.94.9, AS13335) and uses a low-trust SSL certificate (WE1). As of the latest scan, 17 out of 95 security vendors on VirusTotal flagged this domain as malicious, and it appears on at least one security blocklist. The domain has since been taken offline, but its infrastructure remains a potential risk for future reactivation. If you visited t-mobile.yanzx.cc or entered any credentials, immediate action is required. First, change the password for your T-Mobile account and any other accounts where the same credentials may have been reused. Enable multi-factor authentication (MFA) on all critical accounts to prevent unauthorized access. Monitor your accounts for suspicious activity, such as unauthorized logins or transactions, and report any anomalies to T-Mobile’s fraud department. If financial information was entered, contact your bank or card issuer to secure your accounts. Finally, scan your device for malware using updated security software to ensure no additional compromise has occurred.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание