Phishing detection: es-ibercaja.blamedame.com

Ibercaja
http://es-ibercaja.blamedame.com/signin/login.html Access site
Screenshot
Screenshot of es-ibercaja.blamedame.com

Screenshot captured by urlscan.io on 2026-09-11T13:01 UTC: our own render of this page came back blank.

Investigate
Domain es-ibercaja.blamedame.com7 CT hosts on apex
URL http://es-ibercaja.blamedame.com/signin/login.html
Phishunt analysis Beta
30 low suspicionheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +4.1 Site cluster
  • +3.0 OpenPhish
  • +2.6 Brand in subdomain
  • +2.2 Country mismatch
  • +1.7 Shared IP cluster
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.6 Login text in screenshot
  • +0.6 Script exfil endpoint
  • +0.5 Long domain
  • +0.4 Credential path
  • +0.2 Suspicious TLD
  • +0.1 Hyphens
  • +0.1 Deep subdomain
17 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Impersonates Ibercaja, a Spanish bank, via a fake sign-in page hosted in the Netherlands on unrelated infrastructure. Google Safe Browsing flags it as social engineering, and a script exfiltration endpoint indicates active credential theft in progress.

Google Safe BrowsingScript exfil endpointOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-11 · confidence 93%
Domain & Network
Whois
Registrar IONOS SE
Network
Country The NetherlandsThe Netherlands
ASN AS14956
TLS Cert -
External detection Google Safe Browsing OpenPhish
GSB category: SOCIAL_ENGINEERING
CleanPhishTank · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-09-11 13:03 UTC  ·  Last refreshed 2026-09-11 15:30 UTC