t-mobile[.]irfae[.]cc
“irfae.cc | 521: Web server is down”
t-mobile.irfae.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 20/93 (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); Google Safe Browsing flagged; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain t-mobile.irfae.cc is currently serving a "521: Web server is down" page, indicating the site is offline. It is flagged by Google Safe Browsing for "SOCIAL_ENGINEERING," suggesting it is designed to deceive users into performing actions or divulging information, likely impersonating the T-Mobile brand based on the subdomain. The threat is phishing or credential theft targeting T-Mobile customers.
Technical evidence shows this site is flagged by 20 out of 95 VirusTotal vendors, including ADMINUSLabs, Criminal IP, BitDefender, Cluster25, and CRDF. The domain was created on 2026-02-21 and registered with Gname.com Pte. Ltd. It resolves to IP address 2a06:98c1:3121::3 in the United States, hosted on AS13335 Cloudflare, Inc. The SSL certificate is issued by Google Trust Services / WE1, and nameservers are sandra.ns.cloudflare.com and santino.ns.cloudflare.com.
The site is currently down/offline with a domain risk score of 83, indicating a high threat level. Despite being inactive, the domain remains registered and could be reactivated for malicious campaigns. The combination of social engineering flags, recent creation date, and multiple blocklist entries confirms it is a high-risk asset.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。