t-mobile[.]ljouf[.]cc
“T-Mobile Tuesdays - Get Free Stuff & Great Deals | T-Mobile”
t-mobile.ljouf.cc — 内容不可用 (HTTP 502). 品牌冒充:Apple; 诈骗类型:Tech Support Scam. 证据摘要: VirusTotal 16/95 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain t-mobile.ljouf.cc was registered on January 12, 2026 through Gname.com Pte. Ltd. and is currently listed as offline. Technical analysis shows it resolves to the IP address 172.67.185.154, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The domain uses the nameservers A.SHARE-DNS.COM and B.SHARE-DNS.NET and presents an SSL certificate labelled WE1.
The page title returned from the web server is "T-Mobile Tuesdays - Get Free Stuff & Great Deals | T-Mobile," yet the intelligence categorises the activity as a tech support scam that impersonates Apple, indicating a brand‑impersonation vector. Reputation services assign a trust score of 0/100 on both Scamadviser and Gridinsoft, reflecting a complete lack of credibility. The domain appears on a single security blocklist, specifically PhishDestroy, and VirusTotal records show that 16 of 95 scanning vendors flagged the host as malicious, reinforcing the suspicion of abusive use.
Although the site is presently taken offline, the combination of a low trust score, presence on a phishing blocklist, multiple vendor detections, and the mismatched page title strongly suggests that the domain was intended to lure victims by masquerading as a legitimate Apple‑related tech support interaction. Defenders should continue to block the domain at network perimeter controls, monitor the associated IP range for any reactivation, and incorporate the indicator set—domain name, IP address, nameservers, and SSL fingerprint—into threat‑intel feeds. Further investigation is warranted to determine whether additional infrastructure shares the same hosting environment, but based on the available evidence the domain poses an elevated risk and should be treated as hostile.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。