portalbbva[.]mx243[.]com[.]mx
“portalbbva.mx243.com.mx”
portalbbva.mx243.com.mx — Контент недоступен. Сводка доказательств: VirusTotal 15/93 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); PhishDestroy score 100/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On 23 July 2026, analysis of the domain portalbbva.mx243.com.mx identified it as a confirmed phishing infrastructure. The site’s HTML title field returned the exact string “portalbbva.mx243.com.mx”, providing a clear indicator of its malicious intent. The domain was registered on 21 February 2026, suggesting a short lifespan consistent with typical phishing campaigns. VirusTotal scans returned 15 positive detections out of 93 security vendors, indicating that a substantial portion of commercial scanners flagged the host as malicious.
Independent blocklisting services have also marked the domain; it appears on at least one security blocklist and has been actively blocked by the PhishDestroy anti‑phishing feed. Reputation scoring services further corroborate the threat profile: Gridinsoft assigned a trust score of 0 out of 100, while Scamadviser gave a score of 1 out of 100, both reflecting an extremely low level of legitimacy. The current operational status is offline, which may be the result of takedown actions or the natural expiration of the short‑lived registration. No additional intelligence such as hosting IP, ASN, or SSL certificate details is presently available, leaving the hosting infrastructure uncharacterized.
Defenders should continue to block the domain at perimeter controls, update internal URL filtering lists, and monitor for any re‑registration attempts or look‑alike domains that reuse the “portalbbva” identifier. Because the domain has already been flagged by multiple vendors, automated remediation based on the VirusTotal detection count and blocklist presence is recommended. Ongoing threat‑intel feeds should be consulted for any emerging indicators that associate the same naming pattern with new phishing deployments.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание