bvn546fgd[.]shop
“首页”
bvn546fgd.shop — Non verificato. Simulazione del marchio: Generic; Tipo di truffa: Impersonation. Riepilogo delle prove: VirusTotal 15/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of bvn546fgd.shop as of July 28, 2026 shows the domain is currently active and has been identified as a generic phishing operation. The domain resolves to the IPv4 address 47.242.217.10 and is delegated to the authoritative name servers launch1.spaceship.net and launch2.spaceship.net, both of which are typical of publicly available DNS services. The domain has been blocked by PhishDestroy and appears on one additional security blocklist, confirming that multiple threat‑intelligence feeds consider it malicious. VirusTotal scans reported that four out of ninety‑one antivirus and URL‑filtering engines flagged the domain, indicating a non‑negligible detection rate across independent scanners. No public information was found regarding SSL/TLS certificates, HTTP response codes, page title, or content analysis, so the exact visual or functional characteristics of the site remain unknown.
The lack of observed TLS certificates suggests the site may be serving content over plain HTTP, a condition that can facilitate credential capture through unencrypted forms. No WHOIS data was supplied, leaving the registrar, registration date, and ownership details undisclosed. The limited visibility of the hosting environment, combined with the presence on a blocklist and multiple vendor detections, suggests the infrastructure is being leveraged to host phishing lures, likely targeting credential theft. Defenders should immediately block DNS resolution for bvn546fgd.shop and the associated IP 47.242.217.10 at perimeter firewalls and proxy devices.
Continuous monitoring of outbound traffic for connections to the identified name servers and IP address is advised, as well as inclusion of the domain in internal threat‑intel feeds. Because the domain is still active, periodic re‑scanning with sandbox and URL‑reputation services is recommended to capture any evolution in payload or hosting changes.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo