t-mobile[.]smbfw[.]cc
“Welcome to nginx!”
t-mobile.smbfw.cc — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, Cluster25); URLQuery 4 alerts; PhishDestroy score 95/100. Kayıt kuruluşu: Gname.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, t-mobile.smbfw.cc, is flagged as a brand impersonation threat designed to deceive users by mimicking T-Mobile, a major telecommunications provider. Analysis indicates the site was structured to exploit brand recognition, likely for credential theft or fraudulent transactions. No crypto drainer kit signatures were detected, but the domain’s infrastructure aligns with known impersonation tactics targeting consumer trust. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 172.67.138.136, hosted on Cloudflare’s network (AS13335). It was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. VirusTotal reports 18 out of 95 security vendors flagging the domain, while it appears on one security blocklist. The absence of an SSL certificate and the default nginx welcome page suggest minimal effort to mask malicious intent, a common trait in short-lived impersonation campaigns. The domain is currently offline, having been taken down following detection by security systems. However, residual risk remains due to the registrar’s history of hosting fraudulent domains and the potential for re-registration under a similar name. Users who interacted with this domain should monitor accounts for unauthorized activity and verify communications through official T-Mobile channels. Organizations are advised to block the domain and IP at the network level to prevent accidental exposure.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | t-mobile.smbfw.cc |
malicious | Sinkholed |
| OpenDNS | t-mobile.smbfw.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.smbfw.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.smbfw.cc |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260125-776137 Recipient: complaint@gname.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin