t-mobile[.]iaguy[.]cc
“Welcome to nginx!”
t-mobile.iaguy.cc — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 13/93 (ADMINUSLabs, Criminal IP, Cluster25, CRDF, CyRadar); URLQuery 4 alerts; PhishDestroy score 89/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
On July 23, 2026, analysis of the domain t-mobile.iaguy.cc was completed. The domain was registered on February 21, 2026 through Gname.com Pte. Ltd. and resolves to the IP address 188.114.96.3, which is listed under AS13335 Cloudflare, Inc. in the United States. Authoritative nameservers are logan.ns.cloudflare.com and naya.ns.cloudflare.com, confirming the use of Cloudflare’s DNS service. The HTTP response returns a generic “Welcome to nginx!” page title and no TLS certificate is presented, indicating the site operates only over plain HTTP. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single security blocklist where it has been flagged by PhishDestroy, which has already taken the site offline.
VirusTotal scans show that 13 of 93 security vendors have flagged the domain as malicious, providing independent corroboration of its abusive nature. The observed behavior matches the declared scam type of brand impersonation targeting the brand x.com. No additional payloads, login forms, or credential‑capture infrastructure have been observed in the limited data set; the lack of an SSL certificate and the generic nginx title suggest a placeholder page rather than a fully‑featured phishing portal. However, the multiple vendor detections and the zero trust score indicate a high likelihood that the domain was used for malicious impersonation.
Uncertainties remain regarding the exact malicious content that may have been served before takedown, as the site is currently offline and no archived snapshots were available. Defenders should continue to block the IP 188.114.96.3 and the domain t-mobile.iaguy.cc at perimeter and DNS layers, monitor for any resurgence of the same infrastructure under alternate subdomains, and update detection rules to include the observed nameserver pattern and the absence of TLS. Network operators are advised to enforce HTTPS‑only policies to reduce accidental connections to non‑TLS sites.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.iaguy.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.iaguy.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.iaguy.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.iaguy.cc |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
PD-20260124-FAE719 Recipient: complaint@gname.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.