t-mobile[.]hpbeg[.]cc
t-mobile.hpbeg.cc — 内容不可用 (HTTP 502). 品牌冒充:Genericcloudflare. 证据摘要: VirusTotal 15/93 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain t-mobile.hpbeg.cc confirms its classification as a T-Mobile-themed credential phishing site, currently offline as of July 23, 2026. The domain was registered on February 21, 2026, and resolves to the IPv6 address 2a06:98c1:3121::3, which is part of Cloudflare, Inc.'s network (AS13335) and geolocated in the United States. Infrastructure analysis reveals the use of Cloudflare hosting, a common tactic to obscure origin servers and evade takedowns.
The domain's SSL certificate, issued by WE1, does not provide additional attribution due to its generic nature. Detection data indicates elevated risk: the domain appears on one security blocklist and is flagged by 15 of 93 security vendors on VirusTotal, suggesting broad recognition of its malicious intent. The specific phishing kit or payload is not yet analyzed, but the domain name and detection context strongly imply a focus on harvesting T-Mobile customer credentials.
Defenders should treat this domain as confirmed malicious and prioritize blocking it at the DNS and network layers. The domain's current offline status may indicate a temporary takedown or evasion attempt; monitoring for reappearance under the same or similar infrastructure is recommended. No additional brand-specific artifacts or page content details are available for further classification at this time.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。