t-mobile[.]zyfks[.]cc
t-mobile.zyfks.cc — 内容不可用 (HTTP 502). 品牌冒充:Genericcloudflare. 证据摘要: VirusTotal 16/93 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of t-mobile.zyfks.cc indicates that the domain was registered on 21 February 2026 and subsequently resolved to the Cloudflare edge address 104.21.12.157, which is announced as AS13335 Cloudflare, Inc. in the United States. The site is currently listed as offline, and the hosting service has taken the domain offline, yet multiple security products continue to flag it. VirusTotal reports that 16 of 93 scanning engines identified malicious behavior associated with the domain, and the domain appears on a single public blocklist. PhishDestroy has already added the domain to its blocklist, confirming its involvement in phishing campaigns.
The SSL certificate presented is identified as "WE1", which does not correspond to a recognized corporate or extended validation certificate and is typical of domains used for malicious impersonation. Gridinsoft assigns a trust score of 0 out of 100, indicating the lowest possible confidence in legitimacy. No additional evidence such as page title, brand targeting, or kit information is available in the current intelligence set, leaving the exact content of the phishing lure undefined.
Defenders should continue to enforce deny‑list rules for the IP 104.21.12.157 and the domain name, monitor for any re‑activation attempts, and consider correlating internal logs for connections to the Cloudflare network during the period after registration. Because the domain is already offline, immediate threat mitigation focuses on preventing accidental re‑use and ensuring that any residual cached URLs are purged from internal proxies and security gateways. Ongoing vigilance is advised, as the underlying infrastructure – a Cloudflare edge node – is shared with many legitimate services, and future malicious actors could reuse the same IP range for new campaigns.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。