Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
t-mobile[.]mpleq[.]cc
“Welcome to nginx!”
t-mobile.mpleq.cc — 未验证. 证据摘要: VirusTotal 13/91 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 93/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, t-mobile.mpleq.cc, is flagged as a brand impersonation threat designed to deceive users by mimicking the legitimate platform x.com. Such sites typically aim to harvest login credentials, personal data, or distribute malware under the guise of a trusted brand. The fraudulent infrastructure may prompt visitors to enter sensitive information, believing they are interacting with an official service, while the data is instead captured by threat actors for malicious purposes like account takeovers or financial fraud. Analysis indicates the domain was registered on January 27, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. Security vendors on VirusTotal have flagged this domain as malicious, with 17 out of 95 engines detecting it as a threat. The domain resolves to the IP address 172.67.136.163, hosted on Cloudflare’s infrastructure (AS13335), which is commonly used to obscure the true origin of phishing sites. Additional indicators include its presence on one security blocklist and a generic nginx welcome page, often a sign of hastily deployed or low-effort malicious infrastructure. If you visited t-mobile.mpleq.cc or entered any information on the site, immediate action is required. First, disconnect the device from the network to prevent potential data exfiltration. Scan the device using updated antivirus software to detect and remove any malware. Change passwords for all accounts accessed from the compromised device, prioritizing financial and email accounts, and enable multi-factor authentication where available. Monitor accounts for unauthorized activity and report the incident to the legitimate platform being impersonated. Users should also consider notifying their financial institutions if payment details were entered, as threat actors may attempt unauthorized transactions.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | t-mobile.mpleq.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.mpleq.cc |
malicious | Sinkholed |
| OpenDNS | t-mobile.mpleq.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.mpleq.cc |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
证据与外部报告
PD-20260202-1E70D9 Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。