verizon[.]ygfi[.]cc
“Welcome to nginx!”
verizon.ygfi.cc — Contenu indisponible (HTTP 502). Résumé des preuves: VirusTotal 12/93 (Criminal IP, Cluster25, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 86/100. Bureau d’enregistrement: Gname.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of verizon.ygfi.cc indicates the domain is currently offline but was actively used for a brand-impersonation campaign targeting the x.com brand. The domain was registered on 21 February 2026 through Gname.com Pte. Ltd. and resolves to the Cloudflare edge address 172.67.134.3, which is associated with ASN 13335 (Cloudflare, Inc.) and located in the United States. The authoritative nameservers are devin.ns.cloudflare.com and liberty.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure. No TLS certificate was presented at the time of inspection, meaning the site served only HTTP content.
The HTTP response delivered an Nginx default page with the title “Welcome to nginx!”, providing no evidence of a credential‑capture interface or branding elements. Reputation signals are uniformly negative: the domain appears on one security blocklist, has a Gridinsoft trust score of 0 / 100, and is listed as blocked by PhishDestroy. VirusTotal scans recorded 12 detections out of 93 antivirus engines, reinforcing the malicious classification. The observed evidence aligns with the reported scam type of brand impersonation, but the exact phishing landing page content was not captured before the takedown, leaving the specific lure or credential‑harvesting mechanism uncertain.
Defenders should continue to block the domain at perimeter filters, monitor for any re‑registration of the same second‑level name, and consider adding the IP address 172.67.134.3 to deny‑list rules if not already covered by Cloudflare‑wide controls. Because the domain uses Cloudflare’s shared infrastructure, additional scrutiny of other subdomains hosted on the same IP may be warranted. Ongoing threat‑intel feeds should be consulted for any resurgence of this indicator, and any internal logs that reference requests to verizon.ygfi.cc should be investigated for possible user exposure before the takedown.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
PD-20260120-FB515D Recipient: complaint@gname.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif