tuvimsa[.]com[.]mx
“TUVIMSA”
Evidence Summary
On July 28 2026 the domain tuvimsa.com.mx was identified as part of a generic phishing campaign. The domain is currently active and returns an HTTP 301 status code, indicating a permanent redirect. VirusTotal records show that the domain has been scanned by 91 security vendors; none of the scanners have raised a detection at the time of analysis. A single security blocklist includes the domain, and the PhishDestroy service reports it as blocked.
The presence on a blocklist and the redirect response demonstrate that the domain is being monitored by at least one anti‑phishing platform, yet the lack of detections from the majority of AV engines does not confirm benign intent. No public information on the registrar, hosting ASN, IP address, SSL certificate, or page title has been disclosed, leaving the underlying infrastructure opaque. Consequently, the exact hosting location, certificate validity, and potential target brand remain uncertain.
Defenders should ingest the domain into corporate URL filtering solutions, enforce blocklist rules, and consider network‑level blocking of the associated IP once it becomes observable. Continuous re‑scanning with VirusTotal and other multi‑engine services is advised to capture any future changes in detection status. Monitoring for the appearance of the domain in additional blocklists or threat‑intel feeds will help maintain situational awareness while the investigation proceeds.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
Technologies
7 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of tuvimsa.com.mx · checked Jul 28, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive