becucu[.]credit
“BECU Online Banking | Secure Credit Union”
becucu.credit — Contenido no disponible (HTTP 502). Tipo de estafa: Banking Phishing. Resumen de las pruebas: VirusTotal 13/94 (alphaMountain.ai, CyRadar, DNS8, Forcepoint ThreatSeeker, Fortinet); URLQuery 6 alerts; CF Radar malicious; PhishDestroy score 89/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of becucu.credit shows a recently registered domain (created 07 Mar 2026) that was used to host a fraudulent banking login page, as indicated by the page title “BECU Online Banking | Secure Credit Union”. The site resolved to IP 5.252.116.244, an address owned by AS207569 I‑SERVERS LTD in Russia. The hosting stack included Nginx behind Cloudflare, with front‑end libraries Chart.js, Tailwind CSS, Unpkg, Tippy.js, Lightbox and jsDelivr, all of which are commonly found in compromised or copycat pages. DNS is served by three dnspod.com name servers (a.dnspod.com, b.dnspod.com, c.dnspod.com).
No TLS certificate was presented, and the site was taken offline at the time of reporting, but historical scans show that 13 of 94 VirusTotal security vendors flagged the domain as malicious. Gridinsoft assigned a trust score of 0/100, and the domain appears on a single external blocklist, with PhishDestroy already enforcing a block. The lack of SSL, low trust score, and multiple vendor detections collectively confirm the presence of a banking phishing infrastructure.
Uncertainty remains regarding the current activity of the underlying server, as the site is offline and no live payloads can be observed. Defenders should continue to block becucu.credit at DNS, proxy, and endpoint layers, monitor for any resurgence of the IP address or associated name servers, and update detection rules to include the observed technology fingerprint. Threat intelligence feeds should be updated to reflect the confirmed banking phishing classification, and any inbound traffic from the associated IP range should be treated as high‑risk.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | becucu.credit |
malicious | Sinkholed |
| OpenDNS | becucu.credit |
phishing | Phishing Block |
| Cloudflare DNS | becucu.credit |
malicious | Sinkholed |
| Hagezi Threat Feed | becucu.credit |
malicious | Sinkholed |
| Quad9 DNS | becucu.credit |
malicious | Sinkholed |
| DNS4EU | becucu.credit |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 14 identified
Utility-first CSS framework for rapid custom UI development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comFast CDN for everything on npm — serves raw files from npm packages.
Free public CDN for open-source projects, serving files from npm and GitHub.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of becucu.credit · checked Mar 8, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.