bic-moi[.]com
Resumo das evidências
This domain, bic-moi.com, is flagged for hosting a fake login portal designed to harvest user credentials through deceptive authentication interfaces. Analysis indicates the threat type aligns with credential phishing, where victims are tricked into entering sensitive login details into fraudulent forms mimicking legitimate services. The elevated risk level stems from the domain's active exploitation history and its infrastructure's association with known malicious campaigns. Infrastructure analysis reveals multiple technical indicators supporting this assessment. The domain was registered on February 21, 2026, through NameSilo, a registrar frequently leveraged by threat actors for its lenient registration policies. It resolves to the IP address 91.92.243.17, hosted under AS202412 (Omegatech LTD) in the Netherlands, a network segment previously linked to phishing and malware distribution. Security vendors on VirusTotal flagged the domain at a rate of 19/95, indicating moderate consensus on its malicious nature. Additionally, bic-moi.com appears on one security blocklist and is actively blocked by at least one threat intelligence feed. The SSL certificate, identified as R13, lacks transparency and is commonly associated with short-lived phishing domains. Mitigation steps for this specific threat type include immediate blocking of the domain and its associated IP address (91.92.243.17) at the network perimeter. Organizations should deploy email filtering rules to quarantine messages containing links to bic-moi.com or its subdomains. End-user education should emphasize recognizing fake login pages, particularly those using urgency or spoofed branding to elicit credentials. Security teams are advised to monitor for authentication attempts originating from this domain in logs and implement multi-factor authentication (MFA) to mitigate the impact of credential theft. Given the domain's current offline status, continuous monitoring for reactivation or migration to new infrastructure is recommended.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo