txdmv[.]bcsgh[.]cc
“TxDMV Home | TxDMV.gov”
Сводка доказательств
On 22 July 2026 the domain txdmv.bcsgh.cc was observed and subsequently taken offline. The site was registered on 21 February 2026 and immediately began serving content with the page title “TxDMV Home | TxDMV.gov”. The title suggests an attempt to masquerade as the Texas Department of Motor Vehicles, yet the listed brand target is American Express (Amex), indicating a hybrid brand‑impersonation campaign that may lure victims through a misleading URL while referencing a financial brand. The domain resolves to 104.21.76.222, an address hosted by Cloudflare (ASN 13335) located in the United States. SSL analysis shows the certificate labelled “WE1”, which is typical of automatically‑issued certificates and does not provide any indication of legitimate ownership.
Reputation services flag the domain as highly suspicious. Scamadviser assigns a trust score of 1 / 100, and Gridinsoft rates it 0 / 100. VirusTotal reports five positive detections out of ninety‑three scanned engines, confirming that multiple security products recognize malicious behavior. The domain appears on one external blocklist and is actively blocked by the PhishDestroy mitigation service. No further public threat‑intel feeds (OTX, Safe Browsing) were referenced in the available data.
Because the site is currently offline, direct content analysis is not possible; the exact payload, credential‑harvesting mechanisms, or malicious redirects remain unknown. However, the combination of a recent registration, low trust scores, a generic Cloudflare front‑end, and the presence of a brand‑impersonation label strongly suggests a phishing kit aimed at harvesting Amex credentials. Defenders should add the domain and its IP address to internal block lists, monitor for any future re‑registration of the same second‑level domain, and enforce strict outbound filtering for traffic to Cloudflare edge nodes that are not otherwise whitelisted.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание