verizon[.]vtoifdr[.]cc
“Welcome to nginx!”
verizon.vtoifdr.cc — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 12/93 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 2 alerts; PhishDestroy score 86/100. Kayıt kuruluşu: Gname.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is flagged for elevated-risk brand impersonation targeting X.com, a high-profile social media platform. The infrastructure is designed to deceive users into believing they are interacting with legitimate X.com services, potentially facilitating credential harvesting or account compromise. The threat type is explicitly brand impersonation, not a generic phishing attempt, as evidenced by the domain's design and targeting patterns. Infrastructure analysis reveals the domain verizon.vtoifdr.cc was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with malicious domains. It resolves to IP address 172.67.169.189, hosted on AS13335 (Cloudflare, Inc.), a common obfuscation tactic to mask the true origin of the threat. The domain lacks an SSL certificate, increasing the likelihood of interception or manipulation of user data. VirusTotal detection rates indicate 12 out of 95 security vendors flag the domain as malicious, and it appears on one security blocklist. The page title, 'Welcome to nginx!', suggests either a placeholder or misconfigured server, which may indicate rushed deployment or ongoing testing of the phishing infrastructure. Mitigation steps for this specific threat type include blocking the domain at the network level, particularly for endpoints accessing social media platforms. Organizations should monitor for DNS requests to verizon.vtoifdr.cc and its associated IP address, 172.67.169.189, as these are strong indicators of compromise. Users should be educated to verify the legitimacy of domains claiming affiliation with X.com, especially those using subdomains or unconventional TLDs. Given the domain's current offline status, continuous monitoring is recommended to detect any reactivation or migration to alternative infrastructure. Security teams should also review logs for prior connections to this domain to assess potential exposure.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260128-E0882A Recipient: complaint@gname.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin