betpark-girisler2[.]icu
“Marsbahis Casino- Marsbahis Bahis - Marsbahis Casino Rehberi”
The domain betpark-girisler2.icu was flagged as a generic phishing vector on 2026-08-03. Automated scanning services have recorded the domain in multiple defensive feeds. PhishDestroy has listed the domain as blocked, indicating that its infrastructure has been identified as malicious and is actively being denied access by that service. VirusTotal reports that the domain was submitted to 91 independent scanners; none of the engines currently label the host as malicious, but the absence of a detection does not constitute a safety assurance.
Additionally, the domain appears on a single external blocklist, demonstrating that at least one independent threat-sharing platform has marked it as hostile. No public information is available regarding the registrar, creation date, IP address, hosting ASN, TLS certificate, or HTTP response codes, and the page title or any brand references have not been disclosed. Consequently, the observable evidence is limited to its presence on PhishDestroy and a single blocklist, combined with the fact that it has been scanned by a large number of vendors without triggering a detection.
Defenders should continue to treat the domain as malicious until a thorough content analysis is performed. Recommended mitigation steps include adding the domain to local deny lists, configuring web filters to block any HTTP(S) requests to the FQDN, and monitoring network traffic for connections to the associated IP range once it becomes resolvable. Continuous re-evaluation is advised, as additional threat intelligence may emerge that clarifies the campaign’s scope or reveals the underlying infrastructure.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
SHORTDOT ZONE · PUBLIC EVIDENCE
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-18 12:54:05 UTC
Casino / Gambling License Verification
Technologies · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of betpark-girisler2.icu · checked Aug 3, 2026
Evidence & External Reports
PD-20260803-A6B92D Recipient: abuse@gen.xyz Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive