Domain santander-protocolo.com was registered on July 30 2026 through Hosting Concepts B.V. d/b/a Registrar.eu and is currently delegated to the Openprovider name server set (ns1.openprovider.nl, ns2.openprovider.be, ns3.openprovider.eu). DNS resolution points to the IPv4 address 45.74.47.19, which remains active as of the report date. The domain appears on two public phishing blocklists, PhishDestroy and Phishunt, indicating that it has been observed in phishing campaigns.
VirusTotal reports nine detections out of ninety‑one scanners, confirming that multiple security vendors have identified malicious activity associated with the domain. No additional data on SSL certificates, HTTP response codes, Safe Browsing status, or page title is available in the current intelligence set, leaving the exact content and delivery mechanisms of the site unverified. The infrastructure choices—openprovider name servers and a single IPv4 host—are consistent with recent rapid‑deployment phishing operations.
Defenders should consider adding santander-protocolo.com to URL filtering and DNS sinkhole policies, block traffic to 45.74.47.19 at the network perimeter, and monitor for any related sub‑domains or similar registration patterns. Ongoing observation of the domain’s activity, especially any changes in hosting or detection counts, is advised to maintain situational awareness.