xqu[.]ytq[.]mybluehost[.]me
“Home - Lowser”
xqu.ytq.mybluehost.me — Masqué · accessible. Usurpation de l'identité de la marque : Facebook; Type d'arnaque : Social Media Phishing. Résumé des preuves: VirusTotal 14/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); cloaking observed; PhishDestroy score 93/100. Bureau d’enregistrement: Domain.com.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, xqu.ytq.mybluehost.me, is actively flagged for high-risk brand impersonation targeting Facebook. Analysis indicates the infrastructure has been in place since October 5, 2016, and remains operational as of July 12, 2026. The subdomain resolves to the IP address 50.6.253.218 and is hosted on a platform associated with Bluehost, utilizing a combination of Nginx, Apache HTTP Server, WordPress, MySQL, PHP, and Yoast SEO technologies. The presence of these technologies suggests a structured web environment, likely leveraging a content management system to facilitate the phishing operation. The domain is currently detected by 14 out of 95 security vendors on VirusTotal, a signal of confirmed malicious activity. Additionally, it appears on at least one security blocklist and has been specifically blocked by a threat intelligence feed. The page title, 'Home - Lowser,' does not align with legitimate Facebook branding, further supporting the classification of this domain as part of a phishing campaign. The SSL certificate issued by Let's Encrypt provides encryption but does not mitigate the underlying malicious intent, as fraudulent sites commonly use valid certificates to appear legitimate. What remains uncertain is the full scope of the campaign, including whether this domain is part of a larger network of phishing sites or operates independently. The long-standing registration date may indicate either persistent abuse of an older domain or a more recent compromise of existing infrastructure. Defenders should treat this domain as an active threat, particularly in environments where Facebook credentials are a priority for protection. Network-level blocking of the IP 50.6.253.218 and monitoring for related subdomains under mybluehost.me are recommended actions. Given the high-risk classification, immediate containment measures should be prioritized to prevent credential theft or further exploitation.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 7 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Most widely used open-source HTTP server software.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of xqu.ytq.mybluehost.me · checked Jul 12, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif