bf-capital-gbh[.]com
“BF.capital | Venture Mandates & Financing”
Analysis indicates that the domain bf-capital-gbh.com was registered on July 28, 2026 through the registrar Fewmoretaps OU d/b/a Trustname.com. The domain is delegated to Cloudflare nameservers laila.ns.cloudflare.com and pranab.ns.cloudflare.com, and resolves to the IP address 104.21.45.180. The hosting service is therefore Cloudflare, which provides CDN and DDoS mitigation. The domain has been observed by the PhishDestroy blocklist and appears on a single security blocklist at the time of writing. VirusTotal reports that the site has been scanned by 91 antivirus and URL‑reputation engines, none of which have raised a detection.
The lack of detections does not imply safety, but it indicates that the payload or landing page has not yet triggered signatures in those engines. The infrastructure footprint is minimal: only one IP address and a single registration date, suggesting a short‑lived campaign. Current intelligence classifies the activity as generic phishing, but no specific brand or credential‑capture page has been publicly disclosed. Uncertainty remains regarding the content served, the presence of SSL/TLS certificates, HTTP response codes, and any associated malicious payloads, as no page‑title or content analysis is available.
Defenders should proactively block bf-capital-gbh.com at the DNS layer, consider adding the associated IP 104.21.45.180 to network‑level deny lists, and monitor for any outbound connections to that address. Continuous re‑scanning with multi‑engine services such as VirusTotal is recommended to capture any future changes. Organizations using web‑proxy or secure web‑gateway solutions should include the domain in their URL filtering policies. Given the recent creation date and active status, the domain may be part of an emerging campaign, and early containment can reduce exposure.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of bf-capital-gbh.com · checked Aug 1, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive