BD-S07Report Incident form
BGD e-GOV CIRT
Shows fields for affected domains, logs, timing, impact and technical evidence in a cyber-incident report.
Open official sourceA fake site can borrow the name, logo and payment language of a genuine brand. Replace visual guesswork with a reproducible record of the domain, redirects, file source and device impact.
Before tapping a link in a message or advertisement, copy its destination. Preserve the shortener, tracking address, redirects and final hostname separately. If a mobile browser hides the address bar, reveal it or use the share sheet to copy the full URL. Keep a text copy as well as the screenshot so it can be searched, compared and submitted. Look for Unicode lookalikes, extra hyphens, swapped letters, unfamiliar subdomains and misleading paths.
Domain age and a TLS padlock are not safety verdicts. HTTPS can protect transport without proving controller identity, licensing or clean software. WHOIS privacy is not a scam finding either. Stronger records include an authority advisory, confirmed brand ownership, registrar or hosting action, malware analysis and reproducible redirects. Preserve the date and exact domain scope of each source.
BGD e-GOV CIRT's 17 May 2026 advisory describes a Bangladesh-targeting AsyncRAT campaign, fraudulent gambling infrastructure, local-payment lures and ck44jili[.]com as a command-and-control node. It records a malicious executable, scheduled-task persistence and mitigation for credential and financial risk. That is an official technical finding rather than a user allegation.
The finding cannot automatically be applied to another similar name, mirror, affiliate page or unrelated casino. Preserve exact indicator matches, dates and the authority's scope. Defang dangerous domains in text to prevent accidental visits. This site never makes an operator address clickable; the official advisory may be cited as a clickable public-authority source.
| Signal | Preserve | Immediate response |
|---|---|---|
| Lookalike URL | Full hostname, referral, redirect, time | Stop login and payment |
| App or executable download | File name, source URL, size, safe hash | Do not execute; isolate device |
| OTP or PIN prompt | Prompt and domain | Do not disclose; secure provider account |
| Remote-control request | App, permissions, caller identity | End session and revoke access |
| Unexpected task or process | Alert, task name and time | Reset credentials from a clean device |
| Payment lure | Recipient, amount, reference, message | Create a separate provider complaint |
Executing a file or continuing to sign in on an affected device is not good evidence preservation. Disconnecting the network, reviewing sensitive sessions and changing credentials from a clean device may take priority. Before removing a suspicious app, note its name, package, permissions, source and installation time. Seek professional incident response for an enterprise or high-value account.
The CIRT report form asks about the affected domain or IP, logs or an evidence archive, incident type, discovery, attack vector, ongoing status, impact and steps already taken. Provide a concise chronology rather than screenshots alone. Follow authority instructions before packaging malware; never attach an executable to ordinary email or this site's contact form.
When a site copies a genuine brand's logo, that brand may also be a victim. Without domain control, shared infrastructure, official acknowledgement or relationship evidence, do not assign the clone's payment, malware or support conduct to the genuine entity. A brand denial is not conclusive by itself either; compare it with authority and technical evidence.
A report can verify that a user observed a URL, downloaded a named file and received a device alert. The statement that a brand hacked the phone is an attribution claim and remains blocked without controller evidence. This careful distinction gives authorities useful indicators instead of weakening the report.
Prepare route-specific copies from the same preserved originals.
The original message, exported chat, browser history and security alert may preserve the URL without revisiting the affected page. A missing screenshot does not make contemporaneous messages and device logs useless. Follow authority instructions for safe collection rather than attempting malware analysis yourself.
If a platform removes the link after a report, record the removal time. Unavailability does not erase the earlier observation, but it also does not establish maliciousness by itself.
A CIRT or security report can include domain, path, first and last seen times, redirects, download name, safely obtained hash, device warning and impact. Exclude passwords, OTPs, wallet PINs and full identity images. Do not bundle a harmless screenshot with a suspicious executable. If a team requests a malware sample, use its approved secure-transfer instructions. DNS and hosting coincidences are insufficient for public attribution. After takedown, record the actor, timestamp and reference; removal alone does not prove who controlled the domain or establish criminal intent.

BD-S07BGD e-GOV CIRT
Shows fields for affected domains, logs, timing, impact and technical evidence in a cyber-incident report.
Open official sourceBD-S09BGD e-GOV CIRT
Records a dated campaign involving fake software, malware and local-payment lures; it does not justify claims about unrelated domains.
Open official sourceNo scam verdict may be extended beyond the domains and indicators named in the advisory. Each source supports only the narrow proposition stated beside it. Recheck the live authority page before acting. Search snippets, advertising, forums and operator statements are not proof by themselves.
No. HTTPS does not prove controller legitimacy, licensing or absence of malware.
Record the source, file name and time, and do not execute it. Run appropriate device-security checks and use CIRT guidance when relevant.
No. Apply the finding only to exact indicators and infrastructure named by the authority.
Technical indicators may go to CIRT, suspected crime to police or Online GD, and payment loss to the provider through a separate complaint.