t-mobile[.]bpfke[.]cc
“bpfke.cc | 522: Connection timed out”
t-mobile.bpfke.cc — 内容不可用 (HTTP 502). 品牌冒充:T-mobile. 证据摘要: VirusTotal 14/95 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Emsisoft); Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 92/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain t-mobile.bpfke.cc shows that it was registered on 21 February 2026 via Gname.com Pte. Ltd. and is hosted behind Cloudflare (AS13335, United States) using the IP address 172.67.222.90. The authoritative nameservers are ali.ns.cloudflare.com and rocco.ns.cloudflare.com, and the site served an SSL certificate issued by Google Trust Services under the WE1 identifier. HTTP traffic was observed using HTTP/3 and the only visible page title returned by the server was “bpfke.cc | 522: Connection timed out”, indicating that the origin server was unreachable at the time of the query.
The domain is attributed to a t-mobile brand impersonation campaign and is linked to an “Airdrop Scam” phishing kit. Security monitoring records show that the domain was blocked by PhishDestroy, appears on one external blocklist, and has been flagged by 14 of 95 antivirus and URL scanning engines on VirusTotal. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the malicious classification.
The current status is offline, so the site is not actively serving content, but the underlying infrastructure—namely the Cloudflare‑protected IP and the associated SSL certificate—remains in place and could be re‑activated. Defenders should continue to block the domain and its resolved IP address in perimeter defenses, add the nameservers and SSL fingerprint to threat‑intel feeds, and monitor for any re‑registration or changes in host status. Since the exact landing page content has not been captured, further observation is advised to detect potential re‑use of the same infrastructure for future t-mobile impersonation attempts.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
证据与外部报告
PD-20260202-D0BB68 Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。