t-mobile[.]sghbf[.]cc
“Welcome to nginx!”
t-mobile.sghbf.cc — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 9/95 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 3 alerts; PhishDestroy score 77/100. Kayıt kuruluşu: Gname.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of t-mobile.sghbf.cc indicates a brand impersonation campaign targeting x.com, active since February 21, 2026. The domain is currently offline but was previously hosted on Cloudflare IP 172.67.164.127 (AS13335, US) with nameservers amalia.ns.cloudflare.com and ken.ns.cloudflare.com. No SSL certificate was observed, and the only HTTP response recorded was a default 'Welcome to nginx!' page title, suggesting either placeholder content or a misconfigured server at the time of detection. Registration details point to Gname.com Pte. Ltd. as the registrar.
Detection coverage is limited but consistent: one security blocklist (PhishDestroy) and 9 of 95 security vendors on VirusTotal flagged the domain as malicious. Gridinsoft assigns a trust score of 0/100, reinforcing the elevated risk classification. The absence of an SSL certificate and the use of a default nginx page may indicate either an early-stage phishing setup or an abandoned attempt, though the registration date and blocklist presence suggest deliberate malicious intent. Defenders should treat this domain as a confirmed phishing indicator.
While the site is offline, the infrastructure (Cloudflare hosting, recent registration) and detection history warrant continued monitoring. Recommended actions include blocking the domain and IP at perimeter defenses, checking logs for prior connections, and alerting users to potential brand impersonation attempts referencing x.com. The lack of detailed page analysis means the exact phishing mechanism remains unconfirmed, but the combination of brand targeting, detection flags, and hosting patterns aligns with known impersonation tactics.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.sghbf.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.sghbf.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.sghbf.cc |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260124-4FE7EB Recipient: complaint@gname.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin