t-mobile[.]ojre[.]cc
“Welcome to nginx!”
t-mobile.ojre.cc — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 11/95 (Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 83/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain t-mobile.ojre.cc indicates that it is currently taken offline but retains a number of malicious indicators. The domain was registered on February 21, 2026 through Gname.com Pte. Ltd. and is hosted on Cloudflare infrastructure, resolving to IP address 104.21.75.136, which belongs to AS13335 Cloudflare, Inc. in the United States. The authoritative nameservers are rachel.ns.cloudflare.com and yew.ns.cloudflare.com, confirming the use of Cloudflare's DNS services. No SSL certificate is presented for the site, and the HTTP response contains the generic page title "Welcome to nginx!", suggesting a default web server configuration rather than a crafted phishing page. The registrar and hosting details, combined with the lack of TLS, are typical of fast‑flux or temporary phishing deployments.
Threat intelligence flags the domain as a brand impersonation targeting x.com. The scam type is explicitly listed as "Brand Impersonation" and the domain appears on at least one security blocklist, specifically PhishDestroy, which has already blocked the host. A reputation assessment by Gridinsoft assigns a trust score of 0 out of 100, indicating the highest level of suspicion. VirusTotal has recorded 11 detections out of 95 scanners, reinforcing the malicious classification.
While the site is offline, the existing artifacts provide sufficient evidence for defensive teams to enact preventive controls. Organizations should add t-mobile.ojre.cc to URL filtering and DNS blocklists, monitor for any future resolution to the same IP range, and enforce TLS inspection policies to capture any potential re‑appearance of the domain under a new certificate. Continuous watch of the Cloudflare IP block for anomalous traffic patterns is advisable, as threat actors often reuse the same hosting provider for related campaigns.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260203-177642 Recipient: complaint@gname.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога