# PhishDestroy threat dossier — pushbet.co.uk ================================================================ Fetched: 2026-07-29 15:47:58 UTC Canonical: https://phishdestroy.io/domain/pushbet.co.uk/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: Gridinsoft, SOCRadar AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 45.60.243.194 (GB, London) ASN: AS19551 Incapsula Inc Hosting org: Incapsula Inc Registrar: Namecheap, Inc. Nameservers: ["kristin.ns.cloudflare.com.", "marek.ns.cloudflare.com."] Page title: PushBet HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: GlobalSign nv-sa / GlobalSign Atlas R46 DV TLS CA 2026 Q2 Expires: 2026-10-25 Status: INVALID chain Fingerprint: eb30ab098445417a1bfefc751a2e8ebe1d7d1f14b47a438c91c9fad01047935c Subject Alternative Names (related infrastructure — often same operator): - 21betshop.com - 21luckybet.com - acelucky.com - africasports.com - bbcasino.com - betelite.com - betneptune.com - betreels.com - betscreamer.com - betsteve.com - betstorm.com - bo-stg.progressplay.net - boomingcasino.com - casino-pp.net - casino.bluefoxcasino.com ... +91 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 21:23:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 16:20:24 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 21:24:49 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] pushbet.co.uk: Confirmed Phishing Site Analysis of pushbet.co.uk, observed on July 27 2026, shows a domain that is actively serving malicious content despite a lack of detections from automated scanning services. VirusTotal records indicate that the domain has been examined by 91 independent vendors, yet none have raised a flag at the time of analysis; this absence of alerts should not be interpreted as evidence of safety. The domain is registered through Namecheap, Inc., and its authoritative DNS is hosted on Cloudflare, using the nameservers kristin.ns.cloudflare.com and marek.ns.cloudflare.com. An HTTP 301 redirect is returned for the root URL, suggesting that traffic is being forwarded to a secondary location that may host the phishing payload. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy feed, confirming that at least one reputable threat‑intelligence source has identified it as malicious. No SSL certificate details, page title, or brand‑specific references are currently available, indicating that deeper content analysis has not yet been published. Defenders should treat pushbet.co.uk as a confirmed phishing vector and incorporate it into existing blocking controls: add the domain to DNS‑based blacklists, update firewall and proxy rule sets to deny outbound connections, and, where possible, enforce sink‑hole redirection for any attempted resolution. Continuous monitoring of the domain’s resolution patterns and any future VirusTotal or blocklist updates is advised, as the threat actor may modify the hosting infrastructure or launch additional campaigns using the same registration footprint. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 4e548d06a6f3be1355bc5963706ef6e3 TLS cert SHA-256: eb30ab098445417a1bfefc751a2e8ebe1d7d1f14b47a438c91c9fad01047935c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/pushbet.co.uk/ JSON API: https://api.destroy.tools/v1/check?domain=pushbet.co.uk Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,484 domains (83,251 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io