wwwbbvanetcash[.]mx243[.]com[.]mx
“Bienvenido”
wwwbbvanetcash.mx243.com.mx — Контент недоступний (HTTP 502). Уособлення бренду: Bbva. Зведення доказів: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, wwwbbvanetcash.mx243.com.mx, was designed to trick users into thinking they are visiting a legitimate BBVA banking portal, specifically the BBVA Net Cash business platform. The site's title, "Bienvenido," mimics a welcome page, but its true purpose is to steal login credentials and sensitive financial information from unsuspecting visitors. The domain is currently offline, but while active, it posed a significant threat to anyone who might have entered their banking details.
PhishDestroy identified this threat through multiple intelligence sources. The domain was created on February 21, 2026, and its SSL certificate is issued by WE1, which is not a trusted certificate authority for major banks. VirusTotal analysis shows that 17 out of 95 security vendors flagged this domain as malicious, indicating broad consensus among security tools. The domain resolves to an IPv6 address, 2606:4700:3033::ac43:a92f, and appears on at least one security blocklist. These technical indicators, combined with the suspicious domain name that includes "bbvanetcash" followed by unrelated subdomains, confirm this was a phishing operation targeting BBVA customers.
If you visited this domain and entered any personal information, especially your BBVA username, password, or one-time codes, you should immediately change your BBVA banking credentials and enable two-factor authentication if available. Contact BBVA's official customer support to report potential compromise and monitor your accounts for unauthorized transactions. Run a full antivirus scan on any device used to access the site, as phishing pages can sometimes deliver malware. Remember, legitimate banking websites will never ask for sensitive information through unsolicited links or suspicious subdomains.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога