promvda[.]alertsbotsg[.]online
“Telegram: Contact @Promvda_bot”
promvda.alertsbotsg.online — Contenido no disponible. Suplantación de marca: Telegram; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 1/93 (Gridinsoft); PhishDestroy score 56/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of promvda.alertsbotsg.online indicates a confirmed brand impersonation campaign targeting Telegram users. The domain, registered on February 21, 2026, resolves to IP 149.154.167.99, which is hosted on AS62041 (Telegram Messenger Inc) in the Netherlands. This infrastructure alignment with legitimate Telegram services increases the risk of deception, as victims may perceive the site as authentic. The page title, 'Telegram: Contact @Promvda_bot,' directly references a Telegram bot, reinforcing the impersonation of official Telegram communication channels.
Technical indicators show limited but actionable detection: one security vendor on VirusTotal flags the domain, and it appears on one security blocklist (PhishDestroy). The domain currently returns an offline status, suggesting takedown or voluntary suspension, though historical activity cannot be ruled out. The SSL certificate, issued by Go Daddy Secure Certificate Authority - G2, provides no inherent malicious signal but does not guarantee legitimacy. Gridinsoft assigns a trust score of 0/100, consistent with high-risk domains.
Defenders should treat this domain as a confirmed phishing resource due to its explicit brand impersonation, Telegram-specific page title, and hosting on infrastructure associated with the targeted brand. Blocklist inclusion at the network and endpoint levels is recommended, along with monitoring for related domains using similar naming patterns (e.g., 'alertsbotsg,' 'promvda'). The offline status does not eliminate risk; historical logs should be reviewed for connections to this domain prior to takedown. No evidence of a specific phishing kit or payload delivery is present in the available data, limiting further technical attribution.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.