t-mobile[.]iyebo[.]cc
“Welcome to nginx!”
t-mobile.iyebo.cc — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 10/93 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 4 alerts; PhishDestroy score 80/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain t-mobile.iyebo.cc indicates a confirmed brand impersonation campaign targeting x.com, classified as elevated risk. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with fraudulent infrastructure. Infrastructure analysis reveals Cloudflare-hosted nameservers (clara.ns.cloudflare.com and jerry.ns.cloudflare.com) and resolution to IP address 172.67.145.166, which belongs to AS13335 Cloudflare, Inc. in the United States. No SSL certificate was detected, increasing the likelihood of interception or tampering during data transmission.
The domain appears on one security blocklist and is actively blocked by PhishDestroy. While the page title 'Welcome to nginx!' suggests a default server configuration—common in hastily deployed phishing kits—the exact content remains unanalyzed. VirusTotal reports flagged the domain by 10 of 93 security vendors, providing further evidence of malicious intent. Gridinsoft assigns a trust score of 0/100, reinforcing its classification as high-risk.
As of July 23, 2026, the domain is offline, though defenders should treat it as a persistent threat vector. Organizations are advised to block the domain and associated IP at the perimeter, monitor for related infrastructure (e.g., subdomains, newly registered lookalikes), and alert users to the impersonation of x.com. Given the use of Cloudflare, additional obfuscation techniques may be employed to evade detection. No evidence of a specific phishing kit or payload is currently available, but the combination of brand impersonation, lack of SSL, and detection by multiple vendors warrants immediate action.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.iyebo.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.iyebo.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.iyebo.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.iyebo.cc |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260124-659DF3 Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب