MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق p14f.xyz
p14f[.]
The domain p14f.xyz was registered on February 2, 2025 through Gname.com Pte.
- VirusTotal
- 13/95
- Blocklists
- No stored match
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
p14f.xyz — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Bet365; نوع الاحتيال: Crypto Gambling. ملخص الأدلة: VirusTotal 13/95 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 89/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
The domain p14f.xyz was registered on February 2, 2025 through Gname.com Pte. Ltd. and is delegated to four name servers under the 1111343.com hierarchy. DNS resolution directs the domain to the IPv4 address 45.196.247.145, which belongs to ASN140224 (Nebula Global LLC) and is geolocated in Hong Kong. The site presented a page title of "welcome-BET365" and was classified as a crypto gambling impersonation of the Bet365 brand. No TLS certificate was observed, indicating that the service operated without HTTPS protection.
Analysis by VirusTotal shows that 13 of 95 scanned security vendors flagged the domain, reflecting a moderate detection consensus. The domain is listed on a single security blocklist and has been blocked by the PhishDestroy platform, reinforcing its malicious reputation. Additionally, AlienVault OTX references the domain in two distinct threat‑intel pulses, providing further corroboration of its use in malicious campaigns. Current monitoring indicates the domain has been taken offline, but its infrastructure—specifically the hosting IP and registrar details—remains observable for attribution.
Defenders should continue to block the domain at network perimeter devices, update URL filtering policies, and monitor for any re‑registration attempts using the same registrar or hosting provider. Threat hunters should query the associated IP address 45.196.247.145 for any residual activity and correlate logs for connections to that address, especially from assets that may interact with Bet365 services. The lack of SSL and the presence of a brand‑specific page title suggest a low‑effort impersonation, yet the detection history warrants elevated vigilance for related crypto‑gambling scams targeting Bet365 customers.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
Casino / Gambling License Verification
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.