h20u[.]top
“welcome-BET365”
h20u.top — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Bet365; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: NameMart.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, h20u.top, is identified as a credential phishing site specifically targeting users of the Bet365 brand. The page title, welcome-BET365, explicitly impersonates the legitimate Bet365 platform, aiming to harvest login credentials or financial information from unsuspecting users. No associated drainer kit has been confirmed at this stage, though the domain exhibits classic brand impersonation tactics. Analysis indicates the domain was registered on May 21, 2026, through NameMart Pte. Ltd. and resolves to the IP address 154.39.104.138, hosted under AS18186 (Nebula Global LLC) in Hong Kong. VirusTotal detection metrics show 17 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is currently blocked by at least one threat intelligence feed. The SSL certificate is issued by Let's Encrypt (R13), a common choice for both legitimate and malicious sites due to its free and automated issuance process. As of the latest assessment, h20u.top has been taken offline, reducing immediate exposure to potential victims. However, the infrastructure remains a residual risk, as the domain could be reactivated or repurposed for further malicious activity. Organizations are advised to monitor for any re-emergence of this domain or similar patterns in newly registered domains under the same registrar or hosting provider. Network-level blocking of the IP address 154.39.104.138 is recommended to mitigate potential lateral movement or secondary infections. Users who may have interacted with the domain should reset credentials and review accounts for unauthorized activity.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | h20u.top |
malicious | Sinkholed |
| OpenDNS | h20u.top |
phishing | Phishing Block |
| DNS4EU | h20u.top |
malicious | Sinkholed |
| Cloudflare DNS | h20u.top |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% विश्वासNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासGeeTest is a CAPTCHA and bot management provider, protects websites, mobile apps, and APIs from automated bot-driven attacks, like ATO, credential stuffing, web scalping, etc.
www.geetest.com 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of h20u.top · checked May 31, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260531-C5EF3C Recipient: abuse@namemart.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।