seesbl-com[.]mx13[.]com[.]mx
“Bienvenido”
seesbl-com.mx13.com.mx — 内容不可用 (HTTP 502). 品牌冒充:BBVA; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. 注册商: PDR.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, seesbl-com.mx13.com.mx, was identified as a brand impersonation threat targeting BBVA customers through a fraudulent login portal. The page title 'Bienvenido' suggests an attempt to mimic legitimate banking authentication pages, likely designed to harvest credentials from unsuspecting users. The domain was operational until recently, posing an elevated risk due to its direct targeting of financial institution customers, a demographic frequently exploited for unauthorized account access and fraudulent transactions. Analysis of the domain reveals multiple technical indicators of malicious activity. The domain was flagged by 18 out of 95 security vendors on VirusTotal, indicating a consensus among detection engines regarding its phishing nature. It appears on two security blocklists, further corroborating its malicious classification. Infrastructure details show the domain was registered on October 25, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with abusive domains. The domain resolved to the IP address 74.48.78.135, hosted under AS35916 (MULTACOM CORPORATION) in the United States, and lacked an SSL certificate, a red flag for secure communications. Users who visited seesbl-com.mx13.com.mx or entered credentials on the site should take immediate action to mitigate potential risks. First, reset passwords for BBVA accounts and any other platforms where the same credentials may have been reused. Enable multi-factor authentication (MFA) on all financial and sensitive accounts to add an additional layer of security. Monitor bank statements and transaction histories for unauthorized activity, reporting any suspicious transactions to the financial institution immediately. If personal or financial information was disclosed, consider placing a fraud alert or credit freeze with relevant credit bureaus to prevent identity theft. Additionally, scan local devices for malware using updated security tools to ensure no secondary infections were introduced.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。