bvn546fgd[.]shop
“首页”
bvn546fgd.shop — Неперевірений. Уособлення бренду: Generic; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 15/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of bvn546fgd.shop as of July 28, 2026 shows the domain is currently active and has been identified as a generic phishing operation. The domain resolves to the IPv4 address 47.242.217.10 and is delegated to the authoritative name servers launch1.spaceship.net and launch2.spaceship.net, both of which are typical of publicly available DNS services. The domain has been blocked by PhishDestroy and appears on one additional security blocklist, confirming that multiple threat‑intelligence feeds consider it malicious. VirusTotal scans reported that four out of ninety‑one antivirus and URL‑filtering engines flagged the domain, indicating a non‑negligible detection rate across independent scanners. No public information was found regarding SSL/TLS certificates, HTTP response codes, page title, or content analysis, so the exact visual or functional characteristics of the site remain unknown.
The lack of observed TLS certificates suggests the site may be serving content over plain HTTP, a condition that can facilitate credential capture through unencrypted forms. No WHOIS data was supplied, leaving the registrar, registration date, and ownership details undisclosed. The limited visibility of the hosting environment, combined with the presence on a blocklist and multiple vendor detections, suggests the infrastructure is being leveraged to host phishing lures, likely targeting credential theft. Defenders should immediately block DNS resolution for bvn546fgd.shop and the associated IP 47.242.217.10 at perimeter firewalls and proxy devices.
Continuous monitoring of outbound traffic for connections to the identified name servers and IP address is advised, as well as inclusion of the domain in internal threat‑intel feeds. Because the domain is still active, periodic re‑scanning with sandbox and URL‑reputation services is recommended to capture any evolution in payload or hosting changes.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога