attvip[.]mx
Verifica phishing e sicurezza per attvip.mx
“Aviso de Privacidad”
attvip.mx — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Att; Tipo di truffa: Generic Phishing. Riepilogo delle prove: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 98/100. Registrar: GoDaddy.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, attvip.mx, is flagged as a generic phishing site designed to mimic legitimate privacy notices, a tactic commonly used to deceive users into disclosing sensitive information. Analysis indicates the domain hosts content titled 'Aviso de Privacidad,' a Spanish-language privacy notice, which is frequently exploited in phishing campaigns targeting Spanish-speaking users. While no specific brand impersonation or drainer kit is confirmed, the domain’s structure and content align with credential harvesting schemes, where victims are tricked into entering login details or personal data under false pretenses. Infrastructure analysis reveals multiple technical indicators of compromise. The domain was registered on March 30, 2021, through GoDaddy.com and currently resolves to the IP address 67.217.36.132, hosted on AS22458 (CONVERGEONE HOLDINGS, INC.) in the United States. It is flagged by 11 out of 95 security vendors on VirusTotal, appears on two security blocklists, and is actively blocked by PhishDestroy and PhishingDB. The SSL certificate is issued by Let's Encrypt (YR1), a common choice for both legitimate and malicious domains, providing minimal assurance of authenticity. The domain’s creation date suggests it has been operational for an extended period, increasing the likelihood of prolonged malicious activity. As of the latest assessment, attvip.mx remains active and poses a high risk to users. While it is blocked by multiple security platforms, the domain’s continued resolution and lack of takedown indicate persistent threats. Users are advised to avoid interacting with this domain, and organizations should implement network-level blocks for 67.217.36.132 and associated indicators. Given the domain’s age and blocklist presence, monitoring for related infrastructure or newly registered lookalike domains is recommended to mitigate further exposure.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 9 identified
Zurb Foundation is used to prototype in the browser. Allows rapid creation of websites or applications while leveraging mobile and responsive technology. The front end framework is the collection of HTML, CSS, and Javascript containing design patterns.
foundation.zurb.com Confidenza al 100%Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com Confidenza al 100%Apache is a free and open-source cross-platform web server software.
httpd.apache.org Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%jQuery Modal is an overlay dialog box or in other words, a popup window that is made to display on the top or 'overlayed' on the current page.
jquerymodal.com Confidenza al 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Confidenza al 100%Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com Confidenza al 100%Analisi di VirusTotal
Analisi della configurazione del sito
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo