t-mobile[.]zfeor[.]cc
“zfeor.cc | 522: Connection timed out”
t-mobile.zfeor.cc — 内容不可用 (HTTP 502). 品牌冒充:T-mobile. 证据摘要: VirusTotal 13/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Emsisoft); URLQuery 4 alerts; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 93/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of t-mobile.zfeor.cc shows a brand‑impersonation infrastructure that was active during early 2026. The domain was registered on February 21 2026 via Gname.com Pte. Ltd. and is hosted on Cloudflare’s network (ASN 13335) in the United States, resolving to 104.21.77.181. DNS resolution points to the Cloudflare authoritative nameservers matias.ns.cloudflare.com and paige.ns.cloudflare.com, and the site served over HTTP/3, indicating a modern CDN configuration. The TLS certificate presented is issued by Google Trust Services under the WE1 root, confirming a valid HTTPS endpoint despite the site returning a 522 “Connection timed out” page title.
Security‑vendor scanning on VirusTotal recorded 13 positive detections out of 93 scanners, and the domain is listed on a single external blocklist. Independent threat‑intel feeds (PhishDestroy) have already taken the site offline, and the Gridinsoft trust score is 0 / 100, reflecting an extremely low reputation. The observed phishing kit is labeled “Airdrop Scam,” and the domain explicitly impersonates the t‑mobile brand.
No additional content was captured, so the exact payload or credential‑harvesting pages remain unknown. Defenders should immediately block the IPv4 address 104.21.77.181 and the domain t-mobile.zfeor.cc at perimeter and endpoint layers, enforce URL filtering for Cloudflare‑hosted domains that resolve to the same ASN, and monitor for any re‑registration attempts. Continued observation of the associated nameservers and certificate fingerprint is advised to detect potential re‑use of the infrastructure for new impersonation campaigns.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.zfeor.cc |
phishing | Phishing Block |
| Cloudflare DNS | t-mobile.zfeor.cc |
malicious | Sinkholed |
| DNS4EU | t-mobile.zfeor.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.zfeor.cc |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
证据与外部报告
PD-20260202-43FBCF Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。