# PhishDestroy threat dossier — placebet.co.uk ================================================================ Fetched: 2026-07-30 07:04:53 UTC Canonical: https://phishdestroy.io/domain/placebet.co.uk/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: CRDF, Gridinsoft, SOCRadar AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 45.60.243.194 (GB, London) ASN: AS19551 Incapsula Inc Hosting org: Incapsula Inc Registrar: Namecheap, Inc. Nameservers: ["dns1.registrar-servers.com.", "dns2.registrar-servers.com."] Page title: PlaceBet HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: GlobalSign nv-sa / GlobalSign Atlas R46 DV TLS CA 2026 Q2 Expires: 2026-10-25 Status: INVALID chain Fingerprint: eb30ab098445417a1bfefc751a2e8ebe1d7d1f14b47a438c91c9fad01047935c Subject Alternative Names (related infrastructure — often same operator): - 21betshop.com - 21luckybet.com - acelucky.com - africasports.com - bbcasino.com - betelite.com - betneptune.com - betreels.com - betscreamer.com - betsteve.com - betstorm.com - bo-stg.progressplay.net - boomingcasino.com - casino-pp.net - casino.bluefoxcasino.com ... +91 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 19:43:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 06:40:34 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 19:44:39 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] placebet.co.uk – Generic Phishing Site Detected Analysis as of July 27, 2026 indicates that placebet.co.uk remains active and is being used in a generic phishing campaign. The domain is registered through Namecheap, Inc. and resolves to the authoritative name servers dns1.registrar-servers.com. and dns2.registrar-servers.com. HTTP requests receive a 301 redirect response, suggesting that the site may forward victims to another location, but the final landing page has not been captured. VirusTotal has processed the domain with 91 scanning engines; none reported a detection at the time of analysis, but the absence of a flag does not constitute evidence of benign behavior. The domain is currently listed on a single security blocklist and is blocked by the PhishDestroy service, confirming that external threat‑intelligence feeds have identified it as malicious. No additional intelligence such as IP address, ASN, geographic location, SSL certificate details, or page title has been disclosed, leaving the hosting infrastructure and potential payload unknown. Defenders should continue to block DNS resolution for placebet.co.uk, add the domain to internal deny lists, and monitor network traffic for connections to the associated name servers. Because the redirect may point to a secondary malicious host, investigators should capture the final URL after the 301 response and assess any subsequent content. Regular re‑scanning with VirusTotal or similar multi‑engine services is recommended to detect any future changes in detection status. Coordination with the registrar (Namecheap) to request suspension may reduce the domain’s availability, though the attacker could migrate to a new domain. Ongoing vigilance is required until the campaign is fully disrupted. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 4e548d06a6f3be1355bc5963706ef6e3 TLS cert SHA-256: eb30ab098445417a1bfefc751a2e8ebe1d7d1f14b47a438c91c9fad01047935c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/placebet.co.uk/ JSON API: https://api.destroy.tools/v1/check?domain=placebet.co.uk Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,589 domains (93,414 alive under monitoring, 99,913 confirmed takedowns/dead). Site: https://phishdestroy.io