84698[.]xyz
“welcome-BET365”
Resumen de las pruebas
On 23 July 2026 the domain 84698.xyz was observed as an offline infrastructure used to impersonate Bet365. The domain was registered on 7 January 2026 through Gname.com Pte. Ltd. and resolves to the IPv4 address 45.196.247.189, which is announced by AS140224 (Nebula Global LLC) and geolocated to Hong Kong. The host presents an SSL certificate identified as R13, indicating the use of a low‑trust certificate. The HTTP response previously returned a page whose title was “welcome‑BET365”, matching the declared brand target Bet365 and the scam type “Crypto Gambling”.
Reputation checks show a Gridinsoft trust score of 0 / 100 and detection by 14 of 93 VirusTotal scanners. The domain appears on a single security blocklist and has been blocked by the PhishDestroy service. AlienVault OTX references the domain in two separate threat‑intel pulses, further confirming its malicious use. The combination of a fresh registration, low trust score, hostile SSL, and multiple vendor detections suggests a purpose‑built phishing or crypto‑gambling lure aimed at Bet365 customers.
No public evidence of the page content, login fields, or payload has been released, so the exact phishing kit or credential‑harvesting technique remains unknown. Analysts should continue to monitor the IP address 45.196.247.189 for any re‑activation, enforce blocklists that include 84698.xyz, and consider adding the ASN or host to network‑level deny lists. Additional scrutiny of other domains registered by the same registrar during the same period may reveal related infrastructure. Defenders are advised to educate Bet365 users about unsolicited links that reference “welcome‑BET365” and to verify TLS certificates before entering credentials.
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | 84698.xyz |
malicious | Sinkholed |
| OpenDNS | 84698.xyz |
phishing | Phishing Block |
| Cloudflare DNS | 84698.xyz |
malicious | Sinkholed |
| DNS4EU | 84698.xyz |
malicious | Sinkholed |
| Hagezi Threat Feed | 84698.xyz |
malicious | Sinkholed |
| Quad9 DNS | 84663.xyz |
malicious | Sinkholed |
| DNS4EU | ssl.gfw301.top |
malicious | Sinkholed |
| DNS0 Zero | ssl.gfw301.top |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.