t-mobile[.]ivctg[.]cc
“T-Mobile Tuesdays - Get Free Stuff & Great Deals | T-Mobile”
t-mobile.ivctg.cc — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Apple; Dolandırıcılık türü: Tech Support Scam. Kanıt özeti: VirusTotal 14/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, ESET); Spamhaus DBL_PHISH; PhishDestroy score 92/100.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
t-mobile.ivctg.cc was registered on 21 February 2026. The site is currently offline, but historical data shows it was hosted behind Cloudflare (AS13335) and resolved to 188.114.96.3, an IP located in the United States. The SSL certificate presented under the label “WE1” is associated with the same host. Reputation services assign a trust score of 0 out of 100 on both Scamadviser and Gridinsoft, indicating a high likelihood of malicious activity. The page title retrieved from the live endpoint reads “T‑Mobile Tuesdays – Get Free Stuff & Great Deals | T‑Mobile”, a clear attempt to borrow the T‑Mobile brand while the underlying campaign is reported to impersonate Apple.
The associated scam type is listed as a Tech Support Scam, suggesting victims may be lured into unsolicited support calls or remote‑access requests. VirusTotal analysis shows that 14 of 93 scanning engines flagged the domain, reinforcing the suspicion of malicious intent. The domain appears on a single public blocklist, PhishDestroy, which has already taken it offline. No additional public blocklists or Safe Browsing entries are recorded.
The combination of a brand‑impersonating page title, zero trust scores, a low‑reputation SSL certificate, and multiple vendor detections provides strong evidence that t-mobile.ivctg.cc was used for credential‑phishing or tech‑support fraud targeting Apple users. Uncertainty remains regarding the exact payload delivered to victims because the site is no longer reachable for content analysis. Defenders should continue to block the domain at perimeter devices, monitor DNS queries for the resolved IP address 188.114.96.3, and add the domain to internal threat‑intel feeds. Incident response teams should also review any recent Apple‑related support tickets for signs of social‑engineering attempts that may have originated from this infrastructure.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin