mail[.]gmq[.]ndh[.]mybluehost[.]me
Domain Security & Threat Intelligence Report
The domain mail.gmq.ndh.mybluehost.me is active and currently impersonates a legitimate email service, making it a potential vector for credential theft. It has received a notable VirusTotal score of 15 out of 95, indicating a concerning level of malicious activity associated with it. Such phishing attempts can trick users into providing sensitive login information, heightening the risk of compromised accounts.
This domain was registered through Domain.com - Network Solutions, LLC and has been operational for over nine years. It is hosted on an IP address (198.18.1.191) that is likely associated with shared hosting, which can enable multiple domains of dubious nature to coexist. The domain has been flagged on two blocklists, signaling its involvement in fraudulent schemes.
Currently, the domain remains active, and PhishDestroy has taken steps to monitor its activities closely. This includes ongoing reporting to relevant authorities to facilitate potential takedown efforts in the future. Vigilance against such phishing operations is crucial for protecting user data and maintaining online safety.
Threat Response Pipeline
Public Blocklist Status
Forensic Evidence Capture
Domain Intelligence
ns2.mybluehost.me
abuse@mail.gmq.ndh.mybluehost.me
contact@mail.gmq.ndh.mybluehost.me
info@mail.gmq.ndh.mybluehost.me
webmaster@mail.gmq.ndh.mybluehost.me
postmaster@mail.gmq.ndh.mybluehost.me
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 198.18.1.191
More Domains at Domain.com - Network Solutions, LLC
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report