bmgssd[.]com
“BigM Express delivery”
Resumo das evidências
Analysis indicates that the domain bmgssd.com was registered on February 21, 2026 and is presently taken offline. DNS resolution points to the IP address 107.172.61.186, which is associated with the HostPapa hosting provider (AS36352) located in the United States. The site presented a page title of "BigM Express delivery," suggesting an attempt to impersonate a courier service under the name BigM Express, although no further branding details are disclosed in the available data. The SSL certificate in use is identified as R10, confirming that HTTPS was configured at the time of observation.
Threat intelligence sources have placed the domain on a single security blocklist, specifically PhishDestroy, which has actively blocked access to the site. Scanning on VirusTotal returned a detection ratio of 2 out of 93 security vendors, indicating that multiple scanners flagged the domain as malicious, though the majority of engines did not raise an alert. No additional public reputation services, such as Google Safe Browsing, have been reported for this domain. The limited evidence set leaves several uncertainties: the exact phishing payload, credential collection mechanisms, and whether the site hosted additional malicious content remain unverified because the site is offline and no page content has been captured.
Defensive teams should prioritize adding bmgssd.com to network deny lists and endpoint protection block rules, especially given its presence on a known phishing blocklist and the positive VirusTotal detections. Continuous monitoring of the hosting IP 107.172.61.186 is advised, as the same infrastructure could be reused for future campaigns. Organizations using email filters should ensure that URLs matching bmgssd.com are quarantined, and security analysts should watch for any resurgence of activity from this domain or related HostPapa assets.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | wss |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo