t-mobile[.]yeiba[.]cc
“Welcome to nginx!”
t-mobile.yeiba.cc — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 12/95 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); PhishDestroy score 86/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, t-mobile.yeiba.cc, operates as a fraudulent login portal designed to impersonate X.com, the social media platform. Its primary threat is credential harvesting, where unsuspecting users are tricked into entering their account details, which are then captured by threat actors. The site may also distribute malware or conduct follow-up phishing attacks using stolen credentials. Given its deceptive design, users who mistake it for the legitimate X.com platform are at high risk of account compromise and potential financial or reputational damage. Analysis indicates this domain is malicious based on multiple technical indicators. It was created on February 21, 2026, through the registrar Gname.com Pte. Ltd., an unusual choice for legitimate services. VirusTotal reports that 12 out of 95 security vendors have flagged the domain as malicious, confirming its involvement in phishing activity. The domain resolves to the IP address 104.21.44.93, hosted on Cloudflare’s infrastructure (AS13335), which is frequently abused for anonymity. Additionally, the site lacks an SSL certificate, a red flag for any modern web service handling user credentials. The page title, 'Welcome to nginx!', further suggests misconfigured or hastily deployed infrastructure, typical of phishing campaigns. If you or someone in your organization visited t-mobile.yeiba.cc, immediate action is required to mitigate risk. First, reset the password for any accounts accessed or entered on the site, using a strong, unique password and enabling multi-factor authentication if available. Scan the device used to visit the domain for malware, as phishing sites often serve malicious payloads. Review account activity for unauthorized logins or transactions, and report any suspicious findings to the platform’s security team. Finally, block the domain and its associated IP (104.21.44.93) at the network level to prevent further exposure. Users should also verify the legitimacy of any unexpected communications claiming to be from X.com or related services.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260130-3B47E4 Recipient: complaint@gname.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание