18322[.]xyz
“welcome-BET365”
18322.xyz — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Bet365; घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 12/91 (alphaMountain.ai, Emsisoft, Forcepoint ThreatSeeker, Fortinet, LevelBlue); URLQuery 7 alerts; PhishDestroy score 94/100. रजिस्ट्रार: GMO Internet.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis indicates that the domain 18322.xyz is actively used in a credential‑harvesting phishing campaign. The domain is listed on one security blocklist and remains flagged as active. DNS resolution points to IP 103.27.177.164, which returns HTTP 200, demonstrating that a web service is operational. VirusTotal reports eight of ninety‑one scanners flag the domain, confirming malicious suspicion. The registrar is GMO Internet Group, Inc. (Onamae.com) and the authoritative nameservers are a10.share-dns.com and b10.share-dns.net, both typical of shared hosting environments. No public page content or specific lure details have been disclosed, so the exact phishing vector and targeted brand remain unknown. Defenders should immediately block 18322.xyz at perimeter and DNS layers, incorporate the IP address into threat‑intel feeds, and monitor for outbound connections to the host. Additional analysis of the web payload, TLS certificates, and traffic patterns is recommended to fully characterize the campaign and to identify any related infrastructure.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | 17644.xyz |
malicious | Sinkholed |
| Cloudflare DNS | 18322.xyz |
malicious | Sinkholed |
| OpenDNS | 18322.xyz |
phishing | Phishing Block |
| DigiCert UltraDNS | 18322.xyz |
malicious | Sinkholed |
| Hagezi Threat Feed | 18322.xyz |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | 18322.xyz |
malicious | Sinkholed |
| DNS4EU | ssl.hw301.xyz |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
थ्रेट इंटेलिजेंस क्रॉस-रेफ़रेंस · source references
तकनीकें · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% विश्वासNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
PD-20260720-E52D15 Recipient: abuse@internet.gmo क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।