clientes-banamex.webcindario.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of clientes-banamex.webcindario.com
The domain clientes-banamex.webcindario.com appears to be a subpage hosted on the webcindario.com free-hosting platform rather than an official standalone corporate domain. Its naming suggests an attempt to target customers of Banamex/Citibanamex, and the page content shown in the screenshot presents a Spanish-language form asking visitors to verify a WhatsApp-linked account and submit a phone number.
Based on the visible content and classification data, the page appears to imitate a financial-services context while using branding elements associated with Citibanamex and messaging references to WhatsApp and Microsoft. This combination is not typical of an official banking login or customer-service portal, and the site does not appear to identify a legitimate operator on the page shown.
The broader web-classification data associates the page with financial services and phishing-related categories. Given the use of a hosted subdomain, brand-referencing name, and credential-style collection form, the website appears to function as a social-engineering landing page rather than a normal banking information site.
Safety Assessment for clientes-banamex.webcindario.com
Multiple independent security signals indicate elevated risk at the time of this scan. The domain was flagged by 20 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, content-malice and anti-phishing databases listed the URL for social-engineering activity, which is a strong indicator compared with weaker heuristic-only detections.
The screenshot also raises concern because it appears to present a verification form tied to Citibanamex while being hosted on a third-party subdomain that does not appear to be an official bank domain. The page asks for a WhatsApp phone number and uses branding references that may be intended to create trust. This kind of setup is commonly associated with credential harvesting or account-takeover lures. A malware scan also reported a generic suspicious object, and the domain's IP address is listed on one mail-reputation blocklist, though that latter signal is secondary and less conclusive than the phishing listings.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Miarroba Networks in Madrid, Spain, using the IP address 5.57.226.202. It appears to be served from a hosted subdomain under webcindario.com rather than from a dedicated official brand domain. DNSSEC is unsigned, which is common but means DNS responses do not appear to benefit from DNSSEC validation.
SSL/TLS information appears inconsistent in the scan results: a certificate expiry date is present, but the scan also reports the SSL state as invalid or missing and the protocol/server details as unknown. That may indicate a misconfiguration, incomplete HTTPS deployment, or scan visibility issue at the time of testing. Combined with the phishing detections and the use of a third-party hosted subdomain for a bank-themed page, the technical profile adds to the overall caution.
Share your experience with this website. Was it safe? Did you encounter any issues?