t-mobile[.]iyebo[.]cc
“Welcome to nginx!”
t-mobile.iyebo.cc — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 10/93 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 4 alerts; PhishDestroy score 80/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain t-mobile.iyebo.cc indicates a confirmed brand impersonation campaign targeting x.com, classified as elevated risk. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with fraudulent infrastructure. Infrastructure analysis reveals Cloudflare-hosted nameservers (clara.ns.cloudflare.com and jerry.ns.cloudflare.com) and resolution to IP address 172.67.145.166, which belongs to AS13335 Cloudflare, Inc. in the United States. No SSL certificate was detected, increasing the likelihood of interception or tampering during data transmission.
The domain appears on one security blocklist and is actively blocked by PhishDestroy. While the page title 'Welcome to nginx!' suggests a default server configuration—common in hastily deployed phishing kits—the exact content remains unanalyzed. VirusTotal reports flagged the domain by 10 of 93 security vendors, providing further evidence of malicious intent. Gridinsoft assigns a trust score of 0/100, reinforcing its classification as high-risk.
As of July 23, 2026, the domain is offline, though defenders should treat it as a persistent threat vector. Organizations are advised to block the domain and associated IP at the perimeter, monitor for related infrastructure (e.g., subdomains, newly registered lookalikes), and alert users to the impersonation of x.com. Given the use of Cloudflare, additional obfuscation techniques may be employed to evade detection. No evidence of a specific phishing kit or payload is currently available, but the combination of brand impersonation, lack of SSL, and detection by multiple vendors warrants immediate action.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.iyebo.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.iyebo.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.iyebo.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.iyebo.cc |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
PD-20260124-659DF3 Recipient: complaint@gname.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.