txdmv[.]bcsgh[.]cc
“TxDMV Home | TxDMV.gov”
Kanıt özeti
On 22 July 2026 the domain txdmv.bcsgh.cc was observed and subsequently taken offline. The site was registered on 21 February 2026 and immediately began serving content with the page title “TxDMV Home | TxDMV.gov”. The title suggests an attempt to masquerade as the Texas Department of Motor Vehicles, yet the listed brand target is American Express (Amex), indicating a hybrid brand‑impersonation campaign that may lure victims through a misleading URL while referencing a financial brand. The domain resolves to 104.21.76.222, an address hosted by Cloudflare (ASN 13335) located in the United States. SSL analysis shows the certificate labelled “WE1”, which is typical of automatically‑issued certificates and does not provide any indication of legitimate ownership.
Reputation services flag the domain as highly suspicious. Scamadviser assigns a trust score of 1 / 100, and Gridinsoft rates it 0 / 100. VirusTotal reports five positive detections out of ninety‑three scanned engines, confirming that multiple security products recognize malicious behavior. The domain appears on one external blocklist and is actively blocked by the PhishDestroy mitigation service. No further public threat‑intel feeds (OTX, Safe Browsing) were referenced in the available data.
Because the site is currently offline, direct content analysis is not possible; the exact payload, credential‑harvesting mechanisms, or malicious redirects remain unknown. However, the combination of a recent registration, low trust scores, a generic Cloudflare front‑end, and the presence of a brand‑impersonation label strongly suggests a phishing kit aimed at harvesting Amex credentials. Defenders should add the domain and its IP address to internal block lists, monitor for any future re‑registration of the same second‑level domain, and enforce strict outbound filtering for traffic to Cloudflare edge nodes that are not otherwise whitelisted.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Adli İstihbarat
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin