w65v[.]xyz
“welcome-BET365”
Evidence Summary
The domain w65v.xyz has been identified as a confirmed phishing site specifically designed to impersonate the well-known online gambling platform Bet365. The threat is classified as brand impersonation, with the domain currently taken offline after being flagged by security researchers. The page title found was "welcome-BET365," a clear attempt to deceive users into believing they are accessing a legitimate Bet365 welcome page.
Technical analysis reveals that w65v.xyz was registered through Gname.com Pte. Ltd. on March 04, 2026, and resolves to the IP address 45.196.247.179. The domain appears on one security blocklist and was flagged by 23 out of 95 VirusTotal vendors, indicating a high likelihood of malicious intent. AlienVault OTX also detected the domain in one threat intelligence pulse, confirming its association with phishing campaigns. The SSL certificate (R12) was likely obtained to give the site a false sense of legitimacy. Despite being taken offline, the domain's creation date is remarkably recent, underscoring the rapid deployment of phishing infrastructure.
Given the elevated risk level and the known intelligence pointing to Bet365 impersonation, users are strongly advised to avoid any interaction with w65v.xyz or similar domains. PhishDestroy recommends verifying any Bet365-related URLs through official channels before entering credentials or personal information. If you have already submitted data to this domain, change your Bet365 password immediately and enable two-factor authentication. Stay vigilant against phishing attempts that exploit trusted brand names.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensic Intelligence
Casino / Gambling License Verification
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive