t-mobile[.]ybkfqh[.]top
“Welcome to OpenResty!”
t-mobile.ybkfqh.top — Контент недоступен (HTTP 502). Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 12/91 (alphaMountain.ai, CRDF, Emsisoft, Fortinet, G-Data); URLQuery 2 det.; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 90/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy identifies t-mobile.ybkfqh.top as a confirmed credential theft site specifically designed to impersonate T-Mobile. This domain is currently offline, but its infrastructure and characteristics indicate a high risk for anyone who may have visited it while active. The site leveraged a deceptive domain structure to mimic legitimate T-Mobile login pages, aiming to harvest usernames, passwords, and potentially financial information from unsuspecting victims.
The domain was flagged by 12 of 95 VirusTotal vendors, a significant signal of malicious intent. It was registered through NameSilo, LLC, and created on May 28, 2026, which is notably a future date, suggesting possible data manipulation or an error. The domain resolves to IP address 188.114.96.3, which is associated with Cloudflare's infrastructure. It also appears on one security blocklist and lacks an SSL certificate, further indicating it was not intended for legitimate secure communications. The page title observed was "Welcome to OpenResty!," a common default page for the OpenResty web platform, which the attackers likely used as a placeholder or misdirection.
Given that t-mobile.ybkfqh.top has been taken offline, the immediate threat from this specific domain is neutralized. However, users who may have interacted with the site while active should change their T-Mobile account credentials immediately and monitor for any unauthorized activity. It is also advisable to enable multi-factor authentication on all accounts where available. PhishDestroy recommends staying vigilant against similar phishing attempts and reporting any suspicious domains to relevant security teams. Always verify the authenticity of URLs before entering sensitive information, especially those claiming to be from well-known brands like T-Mobile.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: ybkfqh.top
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain ybkfqh.top behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of t-mobile.ybkfqh.top · checked May 30, 2026
Доказательства и внешние отчеты
PD-20260530-AB43D4 Recipient: abuse@nic.top Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание