Forensic analysis of a phishing site, tracking of financial assets and criminal infrastructure network (February 2026).
Type: Digital fraudSector: FintechDeliverable: Technical report
Executive Summary
Confirmed the fraudulent transfer via Banxico's CEP, the attacker's complete technical infrastructure identified and documented including exposed control panel and active mail server, two fraudulent domains linked to the same actor through a shared technical indicator, and coordinated disruption recommendations issued to international registrar, CNBV and authorities of three states.
01
Corroborated Facts (Financial Evidence and Identity)
Patrimonial impact confirmed through Banxico's Electronic Payment Receipt (CEP), and the beneficiary's full identity validated via cross-reference with RENAPO (National Population Registry).
Data Point
Verified Detail
Source
Payer (Victim)
SUBJECT-A (Individual, female)
CEP Banxico
Defrauded Amount
$5,190.00 MXN
CEP Banxico
Beneficiary
SUBJECT-B (Confirmed Identity)
CEP Banxico
Beneficiary RFC
[REDACTED]
CEP Banxico
Verified CURP
[REDACTED]
RENAPO / Civil Registry
Beneficiary Origin
State of Mexico
Verified birth certificate
Destination Account
CLABE: ************798642 (Institution: NU MEXICO)
CEP Banxico
Intelligence Note: The cross-validation of Banxico's CEP with RENAPO allowed confirming the full identity of the beneficiary, establishing their state of origin, and linking the declared RFC with a verifiable civil registry. This information was sufficient to substantiate a request for interstate investigative acts.
02
Technological Modus Operandi (Social Engineering)
The website employs advanced deception techniques to simulate official status and urgency.
Identity Theft (Spoofing/Typosquatting)
The domain uses the .cc extension (Cocos (Keeling) Islands) instead of the official .gob.mx, but includes keywords (tramites, express, mx) to mislead the victim. The graphic design replicates exact institutional colors (--passport-green: #0D5D3F) to establish trust.
Fake Tracking ID Generation (Obfuscation)
The site generates a fake tracking number (MXPAS-20260202-MTg3LjE0OS45Ni4xOTg=) not associated with the SRE (Ministry of Foreign Affairs) databases. Forensic code analysis reveals that this number is simply the visitor's IP address encoded in Base64 and dynamically injected to provide a false appearance of authenticity.
False Statements
The source code instructs the victim to believe that SOFIPO "Nu México" accounts are official accounts audited by the SRE, which is legally false and constitutes the deception required for fraud.
03
Attacker's Infrastructure (Technical Attribution)
Digital artifacts were located that allow profiling the attacker and requesting international legal assistance.
Control Panel (C2): The source code exposed the server's internal path, revealing the use of a management panel like HestiaCP or VestaCP, indicating a private VPS.
Real Server IP: Network traffic connects to IP 45.10.243.19, owned by DDoS-Guard.
Mail Server Capability (New Finding): Port analysis (Censys) reveals open ports 143 (IMAP) and 993 (IMAPS), indicating the server also operates as a mail server, likely for email phishing (spam) campaigns.
04
Communication Channels (WhatsApp Social Engineering)
A phone number used to provide false support and "close" the scam was identified.
Detected Number:+52 777 446 XXXX
WhatsApp Profile: Identified as "GOB MX".
Intelligence Analysis:
Inconsistency: Despite using the name "GOB MX", the business description states "Gobi Mx offers a wide range of marketing consultancy services". This suggests an Account Takeover or a reused account.
Area Code Location: The prefix 777 corresponds to Cuernavaca, Morelos.
05
Advanced Forensic Findings (C2 Level)
Through active reconnaissance, evidence confirming manual server administration was obtained.
Visual Confirmation of Control Panel (Port 8083): Visual access to the admin panel was obtained at https://45.10.243.19:8083. The screenshot displays the Hestia Control Panel login, confirming the attacker manages their own VPS (Verified username: adminw).
SSL Fingerprint (Attribution): The self-signed security certificate on the management port was extracted. It contains a unique Common Name: CN=lkasjdsjahsakda.dasdasdsa.sadcom. This data serves as a signature to link other servers to this group.
06
Network Link Analysis (Investigation Expansion)
A second fraudulent platform operated by the same actor has been identified, establishing a serial pattern of behavior.
A. Second Domain Detected
URL: https://www.tramites-y-procesos-oficiales.com/
Evidence of Association: Source code analysis revealed a programming error ("Hardcoded IP"). Both sites contain the variable:
let trackId2 = "187.149.96.198";
Conclusion: Both sites were developed by the same person.
B. Physical Location in Guadalajara
The new site exposes a physical address in Jalisco: Address:Av. Américas 1500, Piso 3, Oficina 302, Col. Providencia, Guadalajara, Jalisco. Suggested Action: Request a physical inspection to verify lease agreements (Virtual Office).
C. Registrar Identification (Kill Switch)
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED (Hong Kong). Abuse Contact:abuse@nicenic.net. Status: Takedown requests have been submitted for both domains.
07
Graphical Representation of the Fraud Scheme
Flowchart representing the victim's ecosystem, the attacker's technical infrastructure, and financial asset tracing.
08
Disruption Strategy and Recommendations
International Takedown Action: Abuse reports sent to abuse@nicenic.net and Cloudflare to disable the domains.
Interstate Investigation Acts:
Jalisco: Inspect the office at Av. Américas 1500.
Morelos: Call logs of the number 777 446 XXXX.
Edomex: Birth registry search in the State of Mexico.
Financial Investigation Focus: Request CNBV (National Banking and Securities Commission) to order Nu México to provide account opening geolocation and flow tracking.
Annexes available in dossier
Annex A: Banxico CEP receipt.
Annex B: RENAPO CURP validation (State of Mexico).
Annex C: Screenshot of HestiaCP control panel at 45.10.243.19.
Annex D: Capture of source code of estafa2.html showing the linking IP 187.149.96.198.
Annex E: Censys Intelligence Report (02/02/2026) confirming Moscow location, open mail ports, and CN=lkasjdsjahsakda.dasdasdsa.sadcom SSL signature.