t-mobile[.]rdabk[.]cc
“Welcome to nginx!”
t-mobile.rdabk.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 13/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; PhishDestroy score 89/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain t-mobile.rdabk.cc has been identified as a brand impersonation phishing threat, specifically targeting X.com. This domain was created on February 21, 2026, and is currently offline, but its malicious intent is confirmed by multiple security sources.
PhishDestroy analysts found that t-mobile.rdabk.cc resolves to the IP address 172.67.201.6 and was flagged by 14 out of 95 VirusTotal vendors, indicating widespread recognition of its malicious nature. The domain appears on one security blocklist and has an SSL certificate from WE1. The page title, "Welcome to nginx!", suggests a generic staging page often used by phishers. Despite its offline status, the domain's creation date and security vendor flags underscore its credibility as a threat.
Users who may have encountered this domain should avoid any interaction and ensure they have not entered credentials or sensitive information. Since the site impersonates X.com, any login details entered could have been compromised. It is recommended to change passwords for any accounts that may have been used on this domain and enable two-factor authentication where possible. PhishDestroy advises monitoring for suspicious activity and reporting any related incidents to the relevant platform. Stay cautious of similar domains and always verify URLs before entering personal information.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。