Bangladesh evidence checks · payment safety · complaint routes
CASINO CHECK BDIndependent public-safety evidence desk
Bangladesh · English editionEvidence reviewed 2026-08-13
Checked directory
Cyber investigation · Bangladesh

Check a fake casino site, clone domain, phishing link or malicious app

A fake site can borrow the name, logo and payment language of a genuine brand. Replace visual guesswork with a reproducible record of the domain, redirects, file source and device impact.

Make the first capture with the address bar visible

Before tapping a link in a message or advertisement, copy its destination. Preserve the shortener, tracking address, redirects and final hostname separately. If a mobile browser hides the address bar, reveal it or use the share sheet to copy the full URL. Keep a text copy as well as the screenshot so it can be searched, compared and submitted. Look for Unicode lookalikes, extra hyphens, swapped letters, unfamiliar subdomains and misleading paths.

Domain age and a TLS padlock are not safety verdicts. HTTPS can protect transport without proving controller identity, licensing or clean software. WHOIS privacy is not a scam finding either. Stronger records include an authority advisory, confirmed brand ownership, registrar or hosting action, malware analysis and reproducible redirects. Preserve the date and exact domain scope of each source.

Keep an official advisory inside its named scope

BGD e-GOV CIRT's 17 May 2026 advisory describes a Bangladesh-targeting AsyncRAT campaign, fraudulent gambling infrastructure, local-payment lures and ck44jili[.]com as a command-and-control node. It records a malicious executable, scheduled-task persistence and mitigation for credential and financial risk. That is an official technical finding rather than a user allegation.

The finding cannot automatically be applied to another similar name, mirror, affiliate page or unrelated casino. Preserve exact indicator matches, dates and the authority's scope. Defang dangerous domains in text to prevent accidental visits. This site never makes an operator address clickable; the official advisory may be cited as a clickable public-authority source.

Signal, evidence and safe response

SignalPreserveImmediate response
Lookalike URLFull hostname, referral, redirect, timeStop login and payment
App or executable downloadFile name, source URL, size, safe hashDo not execute; isolate device
OTP or PIN promptPrompt and domainDo not disclose; secure provider account
Remote-control requestApp, permissions, caller identityEnd session and revoke access
Unexpected task or processAlert, task name and timeReset credentials from a clean device
Payment lureRecipient, amount, reference, messageCreate a separate provider complaint

Do not keep malware running to collect more evidence

Executing a file or continuing to sign in on an affected device is not good evidence preservation. Disconnecting the network, reviewing sensitive sessions and changing credentials from a clean device may take priority. Before removing a suspicious app, note its name, package, permissions, source and installation time. Seek professional incident response for an enterprise or high-value account.

The CIRT report form asks about the affected domain or IP, logs or an evidence archive, incident type, discovery, attack vector, ongoing status, impact and steps already taken. Provide a concise chronology rather than screenshots alone. Follow authority instructions before packaging malware; never attach an executable to ordinary email or this site's contact form.

Do not attribute the clone's conduct to the genuine brand

When a site copies a genuine brand's logo, that brand may also be a victim. Without domain control, shared infrastructure, official acknowledgement or relationship evidence, do not assign the clone's payment, malware or support conduct to the genuine entity. A brand denial is not conclusive by itself either; compare it with authority and technical evidence.

A report can verify that a user observed a URL, downloaded a named file and received a device alert. The statement that a brand hacked the phone is an attribution claim and remains blocked without controller evidence. This careful distinction gives authorities useful indicators instead of weakening the report.

A clean incident bundle for CIRT or police

Prepare route-specific copies from the same preserved originals.

  1. 1Record the defanged full domain and redirect chain.
  2. 2Add discovery source, Bangladesh time and device.
  3. 3Record file name, safe hash, security alert and permissions.
  4. 4Separate credential exposure from payment exposure.
  5. 5List containment actions and remaining impact.
  6. 6Redact identity, OTP, PIN and account data from public copies.
  7. 7Add authority references to the chronology when received.

Do not reopen a dangerous link for a better screenshot

The original message, exported chat, browser history and security alert may preserve the URL without revisiting the affected page. A missing screenshot does not make contemporaneous messages and device logs useless. Follow authority instructions for safe collection rather than attempting malware analysis yourself.

If a platform removes the link after a report, record the removal time. Unavailability does not erase the earlier observation, but it also does not establish maliciousness by itself.

Give specialists reproducible indicators, not exposed secrets

A CIRT or security report can include domain, path, first and last seen times, redirects, download name, safely obtained hash, device warning and impact. Exclude passwords, OTPs, wallet PINs and full identity images. Do not bundle a harmless screenshot with a suspicious executable. If a team requests a malware sample, use its approved secure-transfer instructions. DNS and hosting coincidences are insufficient for public attribution. After takedown, record the actor, timestamp and reference; removal alone does not prove who controlled the domain or establish criminal intent.

Dated CIRT advisory screenshot about fraudulent gambling infrastructure
No scam verdict may be extended beyond the domains and indicators named in the advisory.

Government and public-authority sources used on this page

BD-S07

Report Incident form

BGD e-GOV CIRT

Shows fields for affected domains, logs, timing, impact and technical evidence in a cyber-incident report.

Open official source
BD-S09

Malware campaign using fraudulent gambling infrastructure

BGD e-GOV CIRT

Records a dated campaign involving fake software, malware and local-payment lures; it does not justify claims about unrelated domains.

Open official source

No scam verdict may be extended beyond the domains and indicators named in the advisory. Each source supports only the narrow proposition stated beside it. Recheck the live authority page before acting. Search snippets, advertising, forums and operator statements are not proof by themselves.

Common questions from Bangladesh users

Does a padlock mean the site is safe?

No. HTTPS does not prove controller legitimacy, licensing or absence of malware.

I downloaded an app but did not open it. What now?

Record the source, file name and time, and do not execute it. Run appropriate device-security checks and use CIRT guidance when relevant.

Does a similar word in a CIRT advisory make every related domain malicious?

No. Apply the finding only to exact indicators and infrastructure named by the authority.

Where should I report a clone?

Technical indicators may go to CIRT, suspected crime to police or Online GD, and payment loss to the provider through a separate complaint.