t.it - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned t.it and returned a unknown verdict (score 0). 1 domain and 0 IPs were contacted. 7 malware samples communicate with this URL (Gotango, DCOM, Fileinfector). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 3%
- Scanned URL:
https://t.it/ - Domain: t.it
- Scan tier: fast · observed 2026-08-21 22:22:30 UTC
Malware communicating with this URL (7)
These samples were observed contacting or being served from t.it. Each links to its full analysis.
- Gotango - referenced ·
9d72438542366415407552385b886223· first seen 2026-08-21 - DCOM - referenced ·
7d18fff7b88f96be68f4862a87ab6991· first seen 2026-08-20 - python-3.12.0-amd64.exe - referenced ·
c6bdf93f4b2de6dfa1a3a847e7c24ae1· first seen 2026-08-12 - Gotango - referenced ·
31ea62cc3397d4211f004ac25421e4f3· first seen 2026-08-20 - 46568766300.pdf - referenced ·
d9b4d546b4ce888fb9eb3b5f3dfb1fd4· first seen 2026-08-16 - 6f77be7a27a3ea6993b8defa7f61f442aa1284d63924d4cdf6255e0b102fd0ec - referenced ·
6f77be7a27a3ea6993b8defa7f61f442· first seen 2026-08-14 - Fileinfector - referenced ·
7cb0e62431d1a819fa79cfb3d2edc9d3· first seen 2026-08-14
Why this verdict
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- t.it
- https://t.it/
Other scans of t.it (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - unknown
- 12 Aug 2026 - unknown
Questions about t.it
- Is t.it safe?
- The scan of t.it on 21 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with t.it?
- 7 analysed samples communicate with this URL, including Gotango, DCOM, Fileinfector.
- How was t.it checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of t.it
Scanned on MalwareAnalyzer by Cyble · Open interactive scan