Phishing detection: santandervyg.transcom-fs.com

Banco Santander
https://santandervyg.transcom-fs.com Access site
Screenshot
Screenshot of santandervyg.transcom-fs.com
Investigate
Domain santandervyg.transcom-fs.com10 CT hosts on apex
URL https://santandervyg.transcom-fs.com
Phishunt analysis Beta
17 noiseheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +3.9 Password field
  • +3.0 PhishTank
  • +1.1 ASN reputation
  • +0.7 Brand in cert SAN
  • +0.7 Bulletproof DNS
  • +0.6 Long domain
  • +0.6 Login text in screenshot
  • +0.6 Registrar reputation
  • +0.3 Free CA
  • +0.2 Suspicious TLD
  • +0.1 Hyphens
  • +0.1 External scripts
  • +0.1 Deep subdomain
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates Santander bank under a subdomain of transcom-fs.com, a domain unrelated to the legitimate bank. The TLS certificate SAN contains the Santander brand name and a password input form is present. Confirmed malicious by PhishTank, targeting banking credentials from Santander customers.

PhishTankBrand in cert SANPassword field
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-23 · confidence 90%
Domain & Network
Whois
Network
Country SpainSpain
Hosting acens AS
ASN AS16371
TLS Cert R12
External detection PhishTank
CleanGoogle Safe Browsing · OpenPhish · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-04-15 13:05 UTC  ·  Last refreshed 2026-08-24 03:30 UTC