my[.]satanderbanco[.]online
“Login | Satander Banco”
my.satanderbanco.online is currently offline but historical data show it was used for credential phishing targeting the Satander Banco brand. The site presented the page title "Login | Satander Banco", indicating an attempt to harvest user credentials. Registration occurred on April 14, 2025 through Dynadot Inc and the domain resolved to the IPv4 address 198.12.80.250, which is allocated to AS36352 (HostPapa) in the United States. The hosting provider and IP have been listed on a single public blocklist and the domain is actively blocked by the PhishDestroy service.
The SSL certificate was issued with an R12 rating, suggesting a low‑trust certificate. VirusTotal analysis returned three positive detections out of ninety‑three scanners, reinforcing the malicious classification. Gridinsoft assigned a trust score of 0 out of 100, indicating no confidence in the site’s legitimacy. The intelligence set classifies the operation as generic credential phishing; no additional malware kit or secondary payload information is available.
Uncertainty remains regarding current activity because the site is taken offline and no live HTTP response can be observed. Defenders should continue to enforce URL filtering against the domain and its associated IP address, update internal blocklists, and monitor for any resurrection of the domain or similar look‑alike registrations. Indicator sharing with threat‑intel platforms is recommended, and any attempted credential submissions to the URL should be logged and investigated.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: satanderbanco.online
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain satanderbanco.online behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive