18551[.]xyz
“welcome-BET365”
18551.xyz — Konten tidak tersedia. Peniruan identitas merek: Bet365; Jenis penipuan: Credential Phishing. Ringkasan bukti: VirusTotal 15/91 (alphaMountain.ai, BitDefender, CRDF, ESET, Forcepoint ThreatSeeker); URLQuery 4 alerts; URLScan malicious verdict; Spamhaus DBL_SPAM; PhishDestroy score 95/100. Registrar: GMO Internet.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of the domain 18551.xyz, observed on 21 July 2026, indicates that it is actively hosting a phishing page titled “welcome‑BET365”. The domain was registered on 14 June 2026 through GMO Internet, Inc. and is served by the four nameservers a.share‑dns.com, a8.share‑dns.com, b.share‑dns.net and b8.share‑dns.net. DNS resolution points to the IPv4 address 103.27.177.164, which remains reachable at the time of analysis. VirusTotal reports that 11 of 95 scanned security vendors flag the domain as malicious, confirming a consensus of detection across multiple AV engines. The 11/95 detection ratio reflects a moderate but notable level of malicious confidence among scanning engines, indicating that the site exhibits characteristics commonly associated with credential‑stealing operations. The domain is listed on at least one public security blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing its classification as a high‑risk phishing infrastructure. The available evidence does not disclose the underlying hosting provider, ASN, or geographical location of the IP address, and no SSL certificate details have been observed. Consequently, the full scope of the command‑and‑control infrastructure remains uncertain. The page title suggests an attempt to lure victims into providing credentials related to the BET365 betting platform, but the actual content of the landing page has not been publicly captured, leaving the exact credential‑harvesting mechanism unverified. Further investigation is required to determine whether the site employs additional obfuscation techniques such as URL shorteners or redirects, as no such artifacts have been observed in the current dataset. Defenders should add 18551.xyz to local and network‑level blocklists, monitor DNS queries for the associated nameservers, and enforce outbound traffic filtering to the IP 103.27.177.164.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Referensi Silang Intelijen Ancaman · source references
Teknologi · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org Keyakinan 100%Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Keyakinan 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Keyakinan 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of 18551.xyz · checked Jul 21, 2026
Bukti & Laporan Eksternal
PD-20260721-A69F7E Recipient: abuse@internet.gmo Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive