# PhishDestroy threat dossier — cn.mebetx42.com ================================================================ Fetched: 2026-04-24 21:53:31 UTC Canonical: https://phishdestroy.io/domain/cn.mebetx42.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Gambling Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/95 security vendors flagged this domain Flagging vendors: BitDefender, CRDF, CyRadar, ESET, Fortinet, G-Data, Kaspersky, Lionic, Phishing Database, SOCRadar, Sophos, Trustwave, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 45.200.67.210 (HK, Tung Chung) ASN: ASAS133847 ICT-AS-AP Anpple Tech Enterprise, MY Hosting org: AS133847 Anpple Tech Enterprise Registrar: GoDaddy.com, LLC Nameservers: ["pdns107.ultradns.biz", "pdns107.ultradns.com", "pdns107.ultradns.net", "pdns107.ultradns.org"] Registered: 2026-02-21 Page title: ManBetX(万博体育)官网|英超狼队和水晶宫全球赞助伙伴 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2027-01-05 Status: INVALID chain Fingerprint: 1fea60c24bc3fe8f85c9f8044453521f73a7c16db42dd10b31866ae6f1855298 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-26 23:24:27 UTC (by PhishDestroy tracker) Last verified: 2026-04-13 07:49:34 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019b7ef0-c3ca-71b8-81f1-f3879888ab6b/ Wayback Machine: https://web.archive.org/web/*/cn.mebetx42.com crt.sh CT logs: https://crt.sh/?q=%25.cn.mebetx42.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=cn.mebetx42.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/cn.mebetx42.com URLhaus: https://urlhaus.abuse.ch/host/cn.mebetx42.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-03-19 01:20:49 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies cn.mebetx42.com as a high-risk phishing domain that targeted users by masquerading as the official ManBetX sports sponsorship website. Despite appearing legitimate with a title referencing well-known football clubs, this domain posed significant danger by attempting to deceive visitors into revealing sensitive information. Such phishing sites can lead to identity theft, financial loss, and compromise of personal data. This phishing operation worked by creating a convincing facade mimicking a reputable brand. By registering the domain recently and hosting it on an IP address linked to suspicious activity, attackers aimed to lure victims into submitting login credentials or financial details. The domain was flagged by multiple security sources and appeared on blocklists, confirming its malicious intent. Its takedown reduces immediate risk, but the tactics used highlight the persistent threat of deceptive sports sponsorship scams. If a user visited cn.mebetx42.com, it is crucial to avoid entering any personal or financial data. Users should immediately scan their devices for malware, change passwords for any accounts potentially exposed, and monitor financial statements for unauthorized activity. Reporting the incident to cybersecurity platforms like PhishDestroy helps improve community protection. Staying vigilant about unexpected links and verifying URLs before interaction remains essential to prevent falling victim to similar phishing schemes. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 2e869881151636a789a5922850512a01 TLS cert SHA-256: 1fea60c24bc3fe8f85c9f8044453521f73a7c16db42dd10b31866ae6f1855298 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/cn.mebetx42.com/ JSON API: https://api.destroy.tools/v1/check?domain=cn.mebetx42.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io