Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
t-mobile[.]lbwji[.]cc
“Welcome to nginx!”
t-mobile.lbwji.cc — Неперевірений. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of t-mobile.lbwji.cc shows an active infrastructure that appears to be used for brand impersonation of x.com. The domain was registered on February 21, 2026 through Gname.com Pte. Ltd. and resolves to the IP address 104.21.75.52, which belongs to Cloudflare, Inc. (AS13335) located in the United States. DNS resolution uses the Cloudflare nameservers fattouche.ns.cloudflare.com and ullis.ns.cloudflare.com. A TLS certificate issued by Google Trust Services (WE1) is presented, indicating a valid HTTPS endpoint, yet the HTTP response returns status code 200 with the generic page title "Welcome to nginx!". VirusTotal records indicate that 18 of 93 security vendors have flagged the domain, and Gridinsoft assigns a trust score of 0 out of 100. The domain is currently listed on one security blocklist and has been blocked by PhishDestroy. These indicators collectively suggest a high‑risk phishing operation. Defenders should add the domain to blocklists, monitor traffic to the associated IP, and enforce email filtering rules that detect references to x.com from this host. Continuous observation is advised to capture any changes in payload or hosting configuration.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.lbwji.cc |
phishing | Phishing Block |
| Cloudflare DNS | t-mobile.lbwji.cc |
malicious | Sinkholed |
| DNS4EU | t-mobile.lbwji.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.lbwji.cc |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260202-618798 Recipient: complaint@gname.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога