Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 18 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
3658e100[.]cc
فحص التصيد والأمان للنطاق 3658e100.cc
“bet365”
3658e100.cc — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Bet365; نوع الاحتيال: Impersonation. ملخص الأدلة: VirusTotal 18/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 5 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
The domain 3658e100.cc was registered on 2026-05-03 through Dynadot Inc and is currently resolved to the IPv4 address 40.81.18.27. Both PhishDestroy and OpenPhish have added the domain to their blocklists, and it appears on two additional security blocklists. VirusTotal has recorded 16 positive detections out of 95 scanned vendors, confirming that multiple scanners consider the host malicious. The authoritative name servers are ns1.1233dns.com and ns2.951dns.com, which are commonly observed in other malicious infrastructures.
No public information on SSL certificates, HTTP response codes, or page titles is presently available, and the site has not been publicly analysed for content. The classification provided by the intelligence source is generic phishing, and the risk level is marked high. The domain remains active as of the report date, 2026-07-22, indicating that the threat actor continues to host the malicious payload or credential‑harvesting page. Defenders should immediately block outbound connections to 40.81.18.27 and add 3658e100.cc to DNS‑based deny lists.
Network intrusion detection signatures that match the known name servers or the IP address should be updated. Endpoint protection solutions should be tuned to flag any process that attempts to resolve or contact this domain, and security teams should monitor for any credential‑theft attempts that reference the domain in email or web traffic. Continuous re‑scanning of the domain with sandbox tools is recommended to capture any changes in payload or hosting configuration.
نطاق تغطية البيانات13 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | 3658e100.cc |
malicious | Sinkholed |
| DNS4EU | 3658e100.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | 3658e100.cc |
malicious | Sinkholed |
| OpenDNS | 3658e100.cc |
phishing | Phishing Block |
| Cloudflare DNS | 3658e100.cc |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
المراجع المتقاطعة لاستخبارات التهديدات · source references
التقنيات · 4 identified
Java is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com ثقة 100٪Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of 3658e100.cc · checked Jul 22, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260722-48408E Recipient: abuse@dynadot.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.