t-mobile[.]sghbf[.]cc
“Welcome to nginx!”
t-mobile.sghbf.cc — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 9/95 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 3 alerts; PhishDestroy score 77/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of t-mobile.sghbf.cc indicates a brand impersonation campaign targeting x.com, active since February 21, 2026. The domain is currently offline but was previously hosted on Cloudflare IP 172.67.164.127 (AS13335, US) with nameservers amalia.ns.cloudflare.com and ken.ns.cloudflare.com. No SSL certificate was observed, and the only HTTP response recorded was a default 'Welcome to nginx!' page title, suggesting either placeholder content or a misconfigured server at the time of detection. Registration details point to Gname.com Pte. Ltd. as the registrar.
Detection coverage is limited but consistent: one security blocklist (PhishDestroy) and 9 of 95 security vendors on VirusTotal flagged the domain as malicious. Gridinsoft assigns a trust score of 0/100, reinforcing the elevated risk classification. The absence of an SSL certificate and the use of a default nginx page may indicate either an early-stage phishing setup or an abandoned attempt, though the registration date and blocklist presence suggest deliberate malicious intent. Defenders should treat this domain as a confirmed phishing indicator.
While the site is offline, the infrastructure (Cloudflare hosting, recent registration) and detection history warrant continued monitoring. Recommended actions include blocking the domain and IP at perimeter defenses, checking logs for prior connections, and alerting users to potential brand impersonation attempts referencing x.com. The lack of detailed page analysis means the exact phishing mechanism remains unconfirmed, but the combination of brand targeting, detection flags, and hosting patterns aligns with known impersonation tactics.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.sghbf.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.sghbf.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.sghbf.cc |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260124-4FE7EB Recipient: complaint@gname.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога