MALICIOUS — CRITICAL
t73f.top — Phishing Investigation Report
t73f[.]
Analysis of the domain t73f.top, created on 9 June 2026 and hosted on IP 103.244.148.114, indicates a high‑risk phishing infrastructure.
- VirusTotal
- 12/91
- Blocklists
- No stored match
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
t73f.top — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Bet365; نوع الاحتيال: Impersonation. ملخص الأدلة: VirusTotal 12/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, G-Data); URLQuery 8 alerts; Spamhaus DBL_SPAM; PhishDestroy score 88/100. مسجّل النطاق: NameMart.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
Analysis of the domain t73f.top, created on 9 June 2026 and hosted on IP 103.244.148.114, indicates a high‑risk phishing infrastructure. The domain is delegated to four nameservers (ns1‑ns4.1111343.com) operated by the same provider, suggesting centralized control. VirusTotal reports that 11 of 91 scanning engines flag the domain, providing a moderate confidence level of malicious activity. The same domain appears on two external blocklists and is actively listed by PhishDestroy and OpenPhish, reinforcing the assessment that it is being used for phishing campaigns.
Registration data shows the registrar as NameMart Pte. Ltd., a registrar frequently observed in malicious registrations, though no additional WHOIS details are available. The hosting IP 103.244.148.114 resides in an IP range commonly associated with short‑lived malicious sites, but without reverse‑DNS or ASN information the precise geographic location cannot be confirmed. No SSL certificate details, HTTP response codes, Safe Browsing status, or page‑title information are currently available, leaving the content‑level analysis incomplete.
Defenders should block traffic to t73f.top at perimeter devices, add the domain to DNS sinkhole lists, and monitor for any outbound connections to the associated IP address. Continuous re‑scanning with VirusTotal or similar multi‑engine platforms is advised to capture any changes in detection scores. Organizations using email filtering should ensure that messages containing links to t73f.top are quarantined, and security teams should consider sharing observables with threat‑intel sharing platforms to enrich collective defenses.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات13 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t82a.top |
malicious | Sinkholed |
| DNS4EU | img.esportsdata.cc |
malicious | Sinkholed |
| DigiCert UltraDNS | t73f.top |
malicious | Sinkholed |
| Cloudflare DNS | t73f.top |
malicious | Sinkholed |
| DNS4EU | t73f.top |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | t73f.top |
malicious | Sinkholed |
| OpenDNS | t73f.top |
phishing | Phishing Block |
| DNS4EU | ssl.hw301.xyz |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
المراجع المتقاطعة لاستخبارات التهديدات · source references
التقنيات · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org ثقة 100٪Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260728-A644D8 Recipient: abuse@namemart.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.