# PhishDestroy threat dossier — galabet388.org ================================================================ Fetched: 2026-04-21 19:10:32 UTC Canonical: https://phishdestroy.io/domain/galabet388.org/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 18/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CyRadar, ESET, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Kaspersky, OpenPhish, Seclookup, SOCRadar URLQuery: 2 detections Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.177.120.53 (NL, Amsterdam) ASN: AS22612 Namecheap, Inc. Hosting org: Web-hosting.com Registrar: DYNADOT LLC Nameservers: dns1.namecheaphosting.com, dns2.namecheaphosting.com Registered: 2025-06-21 Page title: Galabet388 | Galabet 388 Bintang Kemenangan Galaksi Hoki HTTP response: 429 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2026-06-22 Status: INVALID chain Fingerprint: a23ae6da05f80ce9db6a156918b7b0b93ae1425889485b9329ea534c84f56b5f Subject Alternative Names (related infrastructure — often same operator): - www.galabet388.org ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-06-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-20 13:36:58 UTC (by PhishDestroy tracker) First reported: 2026-04-20 10:36:12 UTC (abuse notice filed) Last verified: 2026-04-21 20:15:11 UTC Neutralised: 2026-04-21 19:15:11 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019daa74-8c7a-70bb-8b2a-b7f613772880/ URLQuery: https://urlquery.net/report/224a25d1-fd47-46b7-b227-95947c43cc51 Wayback Machine: https://web.archive.org/web/*/galabet388.org crt.sh CT logs: https://crt.sh/?q=%25.galabet388.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=galabet388.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/galabet388.org URLhaus: https://urlhaus.abuse.ch/host/galabet388.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-20 13:38:52 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies galabet388.org as an active credential-harvesting domain posing as a gambling portal titled 'Galabet388 | Galabet 388 Bintang Kemenangan Galaksi Hoki.' The site mimics a legitimate betting interface to trick users into submitting account credentials or payment details. No publicly documented drainer kit has been cataloged yet, but the page’s social-engineering content (Malay phrases, 'galaxy luck' theme) suggests a Southeast-Asian targeted campaign. This domain was flagged by 13 of 95 VirusTotal scanners on launch day and is currently resolved to IP 198.177.120.53 via Dynadot LLC. Registered on June 21, 2025, it already appears on two real-time blocklists—OpenPhish and PhishingArmy—and carries a Sectigo SSL certificate. Google Safe Browsing has not yet blacklisted the page, leaving a narrow but exploitable window for victims. As of today galabet388.org remains online and actively serving phishing content. Immediate defensive actions include network-wide DNS blocking of both the domain and its hosting IP, revocation of the SSL certificate, and user advisories to avoid any credential entry. Despite these countermeasures, the high VT detection rate and low age indicate persistent risk; users should treat any interaction with extreme caution and consider the domain permanently compromised. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260420-6CAE18 Favicon MD5: ea4a6439e117de65c42a292b5b9488b8 TLS cert SHA-256: a23ae6da05f80ce9db6a156918b7b0b93ae1425889485b9329ea534c84f56b5f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/galabet388.org/ JSON API: https://api.destroy.tools/v1/check?domain=galabet388.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io