# PhishDestroy threat dossier — 88483.xyz ================================================================ Fetched: 2026-07-25 04:09:23 UTC Canonical: https://phishdestroy.io/domain/88483.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing Targeted brand: Bet365 ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 17/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Google Safe Browsing, Gridinsoft, LevelBlue, Lionic, SOCRadar, Sophos, VIPRE Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.27.177.163 (HK, Mong Kok) ASN: AS135357 HONG KONG KOWLOON TELECOMMUNICATIONS CO.,LIMITED Hosting org: HONG KONG KOWLOON TELECOMMUNICATIONS CO., LIMITED Registrar: Gname.com Pte. Ltd. Nameservers: ["a7.share-dns.com", "b7.share-dns.net"] Page title: welcome-BET365 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-14 Status: INVALID chain Fingerprint: eb808cfc680fe94d44fcc6b24855f9068491a7d5d6edf75405f8a26099110433 Subject Alternative Names (related infrastructure — often same operator): - 88446.xyz - 88450.xyz - 88458.xyz - 88460.xyz - 88463.xyz - 88464.xyz - 88465.xyz - 88469.xyz - 88470.xyz - 88471.xyz - 88472.xyz - 88473.xyz - 88475.xyz - 88476.xyz - 88477.xyz ... +82 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:00:54 UTC (by PhishDestroy tracker) Last verified: 2026-07-25 04:12:57 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 13:17:10 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Warning: 88483.xyz impersonates Bet365 – credential theft This domain, 88483.xyz, is actively serving a credential‑phishing site that mimics the Bet365 brand, as indicated by the page title “welcome‑BET365”. The site is built on Vue.js front‑end components behind an Nginx web server, enforces HTTP Strict Transport Security, and is delivered through Cloudflare with HTTP/3 support. DNS resolution points to the IP address 103.27.177.163, which is registered to Kowloon Telecommunications Co., Limited in Hong Kong. The domain registration was processed via Gname.com Pte. Ltd. The TLS certificate is issued by Let’s Encrypt (YR1), confirming the use of a valid, publicly trusted certificate but offering no assurance about the content hosted. Google Safe Browsing classifies the URL as a social‑engineering threat, and VirusTotal records 17 of 91 scanned security vendors flagging the domain as malicious. The domain appears on a single public blocklist and is currently listed by PhishDestroy as blocked. Nameservers a7.share‑dns.com and b7.share‑dns.net resolve the domain, suggesting the use of a shared DNS service. While the page title and brand target provide clear evidence of Bet365 impersonation, the lack of publicly released page screenshots or login‑form analysis leaves the exact credential‑capture mechanisms unconfirmed. Defenders should immediately add 88483.xyz to URL and DNS blocklists, monitor outbound connections to the associated IP, and enforce email filtering rules that detect references to “Bet365” and the “welcome‑BET365” title. Continuous threat‑intel feeds should be consulted for any updates on additional indicators such as new hosting IPs or altered certificate details, and user awareness campaigns should remind employees that unsolicited requests to log in to Bet365 via unknown domains are likely fraudulent. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: eb808cfc680fe94d44fcc6b24855f9068491a7d5d6edf75405f8a26099110433 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/88483.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=88483.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,386 domains (59,697 alive under monitoring, 128,126 confirmed takedowns/dead). Site: https://phishdestroy.io