Phishing detection: bbva-app-1-c6c6bqhhg7dqh0a9.mexicocentral-01.azurewebsites.net

BBVA
https://bbva-app-1-c6c6bqhhg7dqh0a9.mexicocentral-01.azurewebsites.net Access site
Screenshot
Screenshot of bbva-app-1-c6c6bqhhg7dqh0a9.mexicocentral-01.azurewebsites.net
Investigate
Domain bbva-app-1-c6c6bqhhg7dqh0a9.mexicocentral-01.azurewebsites.net3 CT hosts on apex
URL https://bbva-app-1-c6c6bqhhg7dqh0a9.mexicocentral-01.azurew…
Cert Microsoft TLS G2 RSA CA OCSP 16
Phishunt analysis Beta
20 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +3.0 OpenPhish
  • +2.6 Brand in subdomain
  • +2.2 Country mismatch
  • +1.2 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +1.0 Site cluster
  • +0.6 Long domain
  • +0.6 Suspicious TLD
  • +0.5 Young certificate
  • +0.4 Hyphens
  • +0.3 Deep subdomain
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates BBVA bank using the brand name in a freshly deployed Azure subdomain in Mexico, targeting Spanish-speaking banking customers. Hyphenated subdomain structure and high keyword score indicate credential harvesting. Flagged by OpenPhish.

OpenPhishBrand in subdomainKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-07 · confidence 80%
Domain & Network
Whois
Registrar MarkMonitor Inc.
Network
Country MexicoMexico
ASN AS8075
External detection OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Report this phishing
PaaS platform Azure App Service
Network / ASN Microsoft Corporation
Registrar MarkMonitor Inc.

Tracked from 2026-09-07 01:02 UTC  ·  Last refreshed 2026-09-12 21:30 UTC