x59f[.]xyz
“welcome-BET365”
x59f.xyz — Contenido no disponible (HTTP 502). Suplantación de marca: Bet365; Tipo de estafa: Crypto Gambling. Resumen de las pruebas: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of x59f.xyz indicates the domain is actively used for a brand‑impersonation campaign targeting Bet365. The site was registered on 14 August 2025 through Gname.com Pte. Ltd., and its authoritative name servers are ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, ns1.dnsbm.com, ns2.dnsbm.com, and ns4. The domain resolves to the IP address 45.196.247.159, which is announced by AS140224 (Nebula Global LLC) and geolocated to Hong Kong. No TLS certificate was observed, implying the site is served over plain HTTP. The page title returned by the server is "welcome‑BET365", matching the declared brand target Bet365 and supporting the classification as a crypto‑gambling impersonation.
Threat‑intel feeds have recorded the domain on a single security blocklist and it is listed in sixteen AlienVault OTX pulses. VirusTotal scanned the domain and fourteen of ninety‑five scanning engines reported a detection, confirming malicious behavior. The domain is also blocked by the PhishDestroy service. These independent observations suggest the infrastructure is recognized by multiple defensive platforms. The current operational status is offline, which may reflect takedown actions or a temporary suspension.
However, the underlying infrastructure—registrar, hosting ASN, and name server configuration—remains visible and could be reused for future campaigns. Defenders should continue to monitor the IP 45.196.247.159 and the associated name servers for re‑registration activity. Adding the domain and its IP to internal block lists, as well as updating URL filtering rules for the Bet365 brand, will reduce exposure. Where possible, threat‑intel platforms should be queried for any resurgence of the domain or related indicators of compromise. Continuous verification of the registrar Gname.com Pte. Ltd. for suspicious registrations is also recommended.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.