bvn546fgd[.]shop
“首页”
Analysis of bvn546fgd.shop as of July 28, 2026 shows the domain is currently active and has been identified as a generic phishing operation. The domain resolves to the IPv4 address 47.242.217.10 and is delegated to the authoritative name servers launch1.spaceship.net and launch2.spaceship.net, both of which are typical of publicly available DNS services. The domain has been blocked by PhishDestroy and appears on one additional security blocklist, confirming that multiple threat‑intelligence feeds consider it malicious. VirusTotal scans reported that four out of ninety‑one antivirus and URL‑filtering engines flagged the domain, indicating a non‑negligible detection rate across independent scanners. No public information was found regarding SSL/TLS certificates, HTTP response codes, page title, or content analysis, so the exact visual or functional characteristics of the site remain unknown.
The lack of observed TLS certificates suggests the site may be serving content over plain HTTP, a condition that can facilitate credential capture through unencrypted forms. No WHOIS data was supplied, leaving the registrar, registration date, and ownership details undisclosed. The limited visibility of the hosting environment, combined with the presence on a blocklist and multiple vendor detections, suggests the infrastructure is being leveraged to host phishing lures, likely targeting credential theft. Defenders should immediately block DNS resolution for bvn546fgd.shop and the associated IP 47.242.217.10 at perimeter firewalls and proxy devices.
Continuous monitoring of outbound traffic for connections to the identified name servers and IP address is advised, as well as inclusion of the domain in internal threat‑intel feeds. Because the domain is still active, periodic re‑scanning with sandbox and URL‑reputation services is recommended to capture any evolution in payload or hosting changes.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive