77145[.]cc
“welcome-BET365”
This domain, 77145.cc, is identified as a credential harvesting phishing infrastructure designed to deceive users into submitting sensitive login credentials, financial details, or personal information. Analysis indicates the site employs common phishing tactics, including cloned login portals, fake authentication prompts, and urgency-driven messaging to manipulate victims. The domain’s infrastructure is optimized for rapid deployment and evasion, making it a persistent threat to both individual and organizational security. Evidence supporting this assessment includes detection by 11 out of 95 security vendors on VirusTotal, with signatures classifying it as generic phishing. The domain was registered on July 20, 2024, through Gname.com Pte. Ltd., a registrar frequently associated with high-turnover malicious domains. It resolves to the IP address 103.27.177.163, which has been linked to other phishing campaigns in recent months. Additionally, the domain appears in one threat intelligence pulse on AlienVault OTX, further corroborating its malicious intent. The SSL certificate, issued by Let’s Encrypt, is valid and commonly used to lend a false sense of legitimacy to phishing sites. Users who have visited 77145.cc or interacted with any content hosted on this domain should take immediate remedial action. Disconnect from the site if still active in the browser and clear all cached data to prevent persistent access. Change passwords for any accounts accessed while the domain was open, prioritizing email, financial, and work-related credentials. Enable multi-factor authentication on all critical accounts to mitigate the risk of unauthorized access. Monitor financial statements and account activity for signs of compromise, such as unauthorized transactions or login attempts. Organizations should block the domain and its associated IP at the network perimeter and conduct a review of endpoint logs for connections to 103.27.177.163 or 77145.cc. Report the domain to internal security teams or relevant threat intelligence platforms to aid in broader mitigation efforts.
Threat Response Pipeline
Public Blocklist Status
Technologies · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% confidenceNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive