helguerosport[.]com[.]ar
“BDVenlínea personas”
helguerosport.com.ar — Неперевірений. Уособлення бренду: Banco de Venezuela; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: nicar.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of helguerosport.com.ar confirms active phishing infrastructure targeting Banco de Venezuela customers. The domain, registered on September 25, 2014, through nic.ar, currently resolves to 167.250.5.65 (AS264649, Argentina) and hosts a site titled 'BDVenlínea personas,' directly referencing the bank's online banking portal. While the domain's age might suggest legitimacy, multiple technical indicators confirm malicious intent: Google Safe Browsing classifies the site as 'SOCIAL_ENGINEERING,' and 21 of 95 security vendors in VirusTotal flag it as malicious. The domain appears on two security blocklists and has been documented in 17 AlienVault OTX threat intelligence pulses. Infrastructure analysis reveals the use of Nginx and jQuery, common in phishing kits, and a Let's Encrypt SSL certificate (R13), which provides HTTPS encryption but does not validate content legitimacy. Nameservers point to dns1.servidoraweb.net, dns2.servidoraweb.net, ns1.nuthost.com, and ns2.nuthost.com, which have been associated with other phishing campaigns. The site remains operational, returning an HTTP 200 status, and is actively blocked by PhishDestroy and PhishingDB. Defenders should treat this domain as high-risk. The combination of brand impersonation, social engineering classification, and cross-vendor detections justifies immediate blocking at the network and endpoint levels. While the exact phishing kit or payload is not yet analyzed, the page title and known intelligence confirm the target as Banco de Venezuela's customer login portal. Further investigation into the hosting provider (NUT HOST SRL) and nameserver infrastructure may reveal additional linked domains.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of helguerosport.com.ar · checked Apr 23, 2026
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога