lacalledelterror[.]mx
“Watch Fear Street Part 1: 1994 | Netflix Official Site”
lacalledelterror.mx — 未验证. 品牌冒充:Netflix; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar, Sophos); PhishDestroy score 78/100. 注册商: Markmonitor.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
lacalledelterror.mx is a Spain-language domain leveraging local soccer passion and a terror-related term to lure victims into a fake sports-betting portal that silently loads a cryptocurrency drainer kit. This high-interaction phishing kit targets Spanish-speaking users primarily in Mexico, duplicating the visual identity of well-known betting brands and injecting obfuscated scripts to drain wallets on connect. Initial intelligence did not reveal any direct brand infringement on the betting side, but the drainer payload is the same family used in other Mexico-based campaigns that mimic house-hold services to harvest mnemonic phrases and private keys.
VT Total score of this site remains 0 detections out of 95 engines, reflecting low global coverage at the moment of scanning. The domain was registered on 23 June 2021 through MarkMonitor, pointing to dedicated IP 44.226.113.145. It holds a valid SSL certificate issued by Google Trust Services, which currently prevents most browsers from showing certificate warnings. As of the latest assessment the site is still active and not yet flagged on any public blocklist, indicating it exploits a brief window between deployment and detection.
PhishDestroy’s investigation started 5cea51 moments after the first telemetry hit; the domain is now under active analysis. Due to the zero detections across engines and absence from blocklists, end-users remain exposed despite none of the browsers or mail filters showing a warning. Recommended actions include immediate endpoint isolation if accessed, revocation of any TLS sessions originating from 44.226.113.145, and black-holing the MarkMonitor name servers until the drainer kit is fully extracted. The current risk is MEDIUM-HIGH despite the low VT score because the drainer can operate without AV detections and crypto losses are irreversible.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
所用技术 · 4 identified
Envoy is an open-source edge and service proxy, designed for cloud-native applications.
www.envoyproxy.io 置信度 100%Analytics / tracking service — collects visitor behavior data for the site owner.
zipkin.io 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of lacalledelterror.mx · checked Apr 25, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。