Potentially Malicious Activity
jfncv.cc
"The primary reason is strong typosquatting and brand impersonation of T-Mobile, confirmed by the 'has_proof_of_intent=TRUE' signal and the use of 't-mobile' in the subdomain of a gibberish domain ('jfncv.cc'). Further evidence includes the domain's recent registration, a high-risk TLD, and a fetch timeout, which is consistent with phishing sites attempting to evade analysis. The URL path 'pay?qr=' strongly suggests a phishing attempt."
Note: This finding is based on scans of specific URLs on the domain, not necessarily the root domain itself.
URLert analyzed recent scan activity for jfncv.cc and found 1 result.
| Status | Target URL | Time |
|---|---|---|
| Malicious | https://t-mobile.jfncv.cc/pay | 1d ago |
Run a real-time investigation to understand the specific threats on any URL from this domain.
This assessment is based on automated analysis and may not be definitive.
Always verify independently before taking action.