# limanbetpronet2yenigiris.vip — SUSPICIOUS > limanbetpronet2yenigiris.vip is an active crypto drainer scam impersonating a betting brand. Virustotal score 0/95. Verify on PhishDestroy before interaction. ## Summary PhishDestroy identifies limanbetpronet2yenigiris.vip as an active crypto drainer campaign under live investigation. This domain purports to belong to a betting operator but is configured to siphon cryptocurrency from victims’ wallets upon wallet connection. No specific drainer kit fingerprint has been extracted from passive DNS at this stage, but the domain’s immediate purpose aligns with clipboard-modifying or Web3 wallet-draining payloads. This domain was flagged on March 30 2024, registered by NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to IP 172.67.156.73 and holds a valid Let’s Encrypt SSL certificate. VirusTotal currently shows 0 detections out of 95 engines as of seed a5e5b2, indicating it remains undetected by most antivirus stacks. The domain has not yet appeared on Google Safe Browsing lists and no third-party blocklists have flagged it. As of writing, the campaign is active with no takedown or block in place. Users should avoid visiting or connecting wallets to this domain. PhishDestroy recommends blocking 172.67.156.73 at the network perimeter and flagging limanbetpronet2yenigiris.vip via DNS sinkholing. Remaining risk is high until the site is deactivated or sinkholed, given the absence of AV detection and fresh certificate issuance. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-30 16:26:37 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 172.67.156.73 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/limanbetpronet2yenigiris.vip - PhishDestroy: https://phishdestroy.io/domain/limanbetpronet2yenigiris.vip/ - LLM endpoint: https://phishdestroy.io/domain/limanbetpronet2yenigiris.vip/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/limanbetpronet2yenigiris.vip/ Last updated: 2026-04-04