txdmv[.]bcsgh[.]cc
“TxDMV Home | TxDMV.gov”
Resumen de las pruebas
On 22 July 2026 the domain txdmv.bcsgh.cc was observed and subsequently taken offline. The site was registered on 21 February 2026 and immediately began serving content with the page title “TxDMV Home | TxDMV.gov”. The title suggests an attempt to masquerade as the Texas Department of Motor Vehicles, yet the listed brand target is American Express (Amex), indicating a hybrid brand‑impersonation campaign that may lure victims through a misleading URL while referencing a financial brand. The domain resolves to 104.21.76.222, an address hosted by Cloudflare (ASN 13335) located in the United States. SSL analysis shows the certificate labelled “WE1”, which is typical of automatically‑issued certificates and does not provide any indication of legitimate ownership.
Reputation services flag the domain as highly suspicious. Scamadviser assigns a trust score of 1 / 100, and Gridinsoft rates it 0 / 100. VirusTotal reports five positive detections out of ninety‑three scanned engines, confirming that multiple security products recognize malicious behavior. The domain appears on one external blocklist and is actively blocked by the PhishDestroy mitigation service. No further public threat‑intel feeds (OTX, Safe Browsing) were referenced in the available data.
Because the site is currently offline, direct content analysis is not possible; the exact payload, credential‑harvesting mechanisms, or malicious redirects remain unknown. However, the combination of a recent registration, low trust scores, a generic Cloudflare front‑end, and the presence of a brand‑impersonation label strongly suggests a phishing kit aimed at harvesting Amex credentials. Defenders should add the domain and its IP address to internal block lists, monitor for any future re‑registration of the same second‑level domain, and enforce strict outbound filtering for traffic to Cloudflare edge nodes that are not otherwise whitelisted.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Inteligencia forense
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.