lacalledelterror[.]mx
“Watch Fear Street Part 1: 1994 | Netflix Official Site”
lacalledelterror.mx — Não verificado. Representação da marca: Netflix; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar, Sophos); PhishDestroy score 78/100. Registrador: Markmonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
lacalledelterror.mx is a Spain-language domain leveraging local soccer passion and a terror-related term to lure victims into a fake sports-betting portal that silently loads a cryptocurrency drainer kit. This high-interaction phishing kit targets Spanish-speaking users primarily in Mexico, duplicating the visual identity of well-known betting brands and injecting obfuscated scripts to drain wallets on connect. Initial intelligence did not reveal any direct brand infringement on the betting side, but the drainer payload is the same family used in other Mexico-based campaigns that mimic house-hold services to harvest mnemonic phrases and private keys.
VT Total score of this site remains 0 detections out of 95 engines, reflecting low global coverage at the moment of scanning. The domain was registered on 23 June 2021 through MarkMonitor, pointing to dedicated IP 44.226.113.145. It holds a valid SSL certificate issued by Google Trust Services, which currently prevents most browsers from showing certificate warnings. As of the latest assessment the site is still active and not yet flagged on any public blocklist, indicating it exploits a brief window between deployment and detection.
PhishDestroy’s investigation started 5cea51 moments after the first telemetry hit; the domain is now under active analysis. Due to the zero detections across engines and absence from blocklists, end-users remain exposed despite none of the browsers or mail filters showing a warning. Recommended actions include immediate endpoint isolation if accessed, revocation of any TLS sessions originating from 44.226.113.145, and black-holing the MarkMonitor name servers until the drainer kit is fully extracted. The current risk is MEDIUM-HIGH despite the low VT score because the drainer can operate without AV detections and crypto losses are irreversible.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Tecnologias · 4 identified
Envoy is an open-source edge and service proxy, designed for cloud-native applications.
www.envoyproxy.io 100% de confiançaAnalytics / tracking service — collects visitor behavior data for the site owner.
zipkin.io 100% de confiançaOneTrust is a cloud-based data privacy management compliance platform.
www.onetrust.com 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of lacalledelterror.mx · checked Apr 25, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo