t-mobile[.]yanzx[.]cc
t-mobile.yanzx.cc — Контент недоступний (HTTP 502). Уособлення бренду: Genericcloudflare. Зведення доказів: VirusTotal 17/95 (ADMINUSLabs, Chong Lua Dao, Cluster25, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, t-mobile.yanzx.cc, operates as a fake T-Mobile login portal designed to harvest user credentials. Victims are tricked into entering their usernames and passwords on a spoofed T-Mobile webpage, which then transmits the stolen data to threat actors. Such attacks are commonly used to gain unauthorized access to personal accounts, conduct identity theft, or facilitate further fraudulent activities like SIM swapping or unauthorized transactions. The site mimics legitimate T-Mobile branding to deceive users into believing they are interacting with an official service. Analysis indicates this domain is part of a phishing infrastructure with multiple technical red flags. The domain was registered on February 21, 2026, through Alibaba Cloud’s registrar, an entity frequently abused for malicious registrations. It is currently hosted on Cloudflare’s network (IP: 104.21.94.9, AS13335) and uses a low-trust SSL certificate (WE1). As of the latest scan, 17 out of 95 security vendors on VirusTotal flagged this domain as malicious, and it appears on at least one security blocklist. The domain has since been taken offline, but its infrastructure remains a potential risk for future reactivation. If you visited t-mobile.yanzx.cc or entered any credentials, immediate action is required. First, change the password for your T-Mobile account and any other accounts where the same credentials may have been reused. Enable multi-factor authentication (MFA) on all critical accounts to prevent unauthorized access. Monitor your accounts for suspicious activity, such as unauthorized logins or transactions, and report any anomalies to T-Mobile’s fraud department. If financial information was entered, contact your bank or card issuer to secure your accounts. Finally, scan your device for malware using updated security software to ensure no additional compromise has occurred.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога