bs-amxpj.com
“澳门新葡京 - Grand Lisboa 娱乐”
Evidence Summary
This domain, bs-amxpj.com, is identified as a phishing site specifically targeting users of the Grand Lisboa Casino brand. The page title, "澳门新葡京 - Grand Lisboa 娱乐," directly references the legitimate casino operator, indicating an intent to deceive visitors into believing they are accessing an official gambling platform. As of the latest verification, the domain has been taken offline, though prior activity remains a documented threat vector for financial fraud and credential harvesting. Analysis of technical indicators reveals multiple red flags. The domain was flagged by 22 of 95 security vendors on VirusTotal, demonstrating broad detection across the cybersecurity industry. It was registered through NameMart Pte. Ltd. on January 31, 2026, an unusually recent creation date that aligns with patterns observed in short-lived phishing campaigns. Infrastructure analysis shows the domain resolved to IP address 154.89.78.15, hosted in Hong Kong under CloudFly Net Inc. The SSL certificate, issued by Let's Encrypt (R13), provides minimal assurance, as it is commonly exploited by threat actors to lend superficial legitimacy. The domain appears on one security blocklist and was previously blocked by enterprise-grade filtering systems. Current status indicates the domain is offline, though residual risk persists due to potential re-activation or migration to similar infrastructure. Organizations and individuals are advised to implement the following measures: block the domain and associated IP (154.89.78.15) at the network perimeter; monitor for newly registered domains containing "amxpj" or "Grand Lisboa" in their naming conventions; and conduct retrospective log analysis to identify any prior interactions with the domain. End users should be alerted to the fraudulent nature of this site, particularly those associated with online gambling or financial transactions in the Asia-Pacific region. Given the elevated risk level, security teams are encouraged to treat any future domains with identical infrastructure or naming patterns as high-priority threats.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bs-amxpj.com |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Public Blocklist Status
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 5 identified
Popular CSS framework for responsive, mobile-first web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of bs-amxpj.com · checked Apr 15, 2026
Community reports
Reported by 1 community member, first seen Apr 15, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
PD-20260415-FCED94 Recipient: abuse@namemart.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive