xqu[.]ytq[.]mybluehost[.]me
“Home - Lowser”
xqu.ytq.mybluehost.me — Encubierto · accesible. Suplantación de marca: Facebook; Tipo de estafa: Social Media Phishing. Resumen de las pruebas: VirusTotal 14/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); cloaking observed; PhishDestroy score 93/100. Registrador: Domain.com.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, xqu.ytq.mybluehost.me, is actively flagged for high-risk brand impersonation targeting Facebook. Analysis indicates the infrastructure has been in place since October 5, 2016, and remains operational as of July 12, 2026. The subdomain resolves to the IP address 50.6.253.218 and is hosted on a platform associated with Bluehost, utilizing a combination of Nginx, Apache HTTP Server, WordPress, MySQL, PHP, and Yoast SEO technologies. The presence of these technologies suggests a structured web environment, likely leveraging a content management system to facilitate the phishing operation. The domain is currently detected by 14 out of 95 security vendors on VirusTotal, a signal of confirmed malicious activity. Additionally, it appears on at least one security blocklist and has been specifically blocked by a threat intelligence feed. The page title, 'Home - Lowser,' does not align with legitimate Facebook branding, further supporting the classification of this domain as part of a phishing campaign. The SSL certificate issued by Let's Encrypt provides encryption but does not mitigate the underlying malicious intent, as fraudulent sites commonly use valid certificates to appear legitimate. What remains uncertain is the full scope of the campaign, including whether this domain is part of a larger network of phishing sites or operates independently. The long-standing registration date may indicate either persistent abuse of an older domain or a more recent compromise of existing infrastructure. Defenders should treat this domain as an active threat, particularly in environments where Facebook credentials are a priority for protection. Network-level blocking of the IP 50.6.253.218 and monitoring for related subdomains under mybluehost.me are recommended actions. Given the high-risk classification, immediate containment measures should be prioritized to prevent credential theft or further exploitation.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 7 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Most widely used open-source HTTP server software.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of xqu.ytq.mybluehost.me · checked Jul 12, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.