t-mobile[.]govk[.]cc
“Welcome to nginx!”
t-mobile.govk.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 18/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as an elevated-risk brand impersonation threat designed to deceive users of x.com. Analysis indicates the infrastructure was specifically engineered to mimic legitimate services while facilitating unauthorized access or data collection, a common tactic in credential harvesting campaigns. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain t-mobile.govk.cc, registered through Gname.com Pte. Ltd. on February 21, 2026, currently resolves to IP 47.86.49.23 (AS45102, Alibaba (US) Technology Co., Ltd., Hong Kong). It lacks SSL certification and displays the default nginx welcome page, suggesting either incomplete deployment or deliberate obfuscation. Security vendors flagged the domain in 18 of 95 VirusTotal scans, while PhishDestroy and one additional blocklist have implemented active protections. The creation date discrepancy (2026) further indicates suspicious registration practices, likely an attempt to bypass temporal-based detection systems. Mitigation requires immediate action from both organizational and individual stakeholders. Network administrators should implement DNS-level blocking for t-mobile.govk.cc and its resolving IP 47.86.49.23, while monitoring for related subdomains or IP adjacencies within the same ASN. Security teams should prioritize user education on brand impersonation tactics, particularly domains combining mobile service terminology with unrelated TLDs. End users should verify domain authenticity through official channels before interaction, especially when encountering unexpected login prompts or account verification requests. Continuous monitoring of certificate transparency logs and passive DNS records is recommended to detect potential re-emergence of this threat infrastructure.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.govk.cc |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260205-EB55FB Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。