m36k[.]xyz
“welcome-BET365”
m36k.xyz — Konten tidak tersedia. Peniruan identitas merek: Bet365; Jenis penipuan: Crypto Gambling. Ringkasan bukti: VirusTotal 21/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, Cluster25, CRDF); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, m36k.xyz, is flagged as a brand impersonation threat specifically targeting Bet365, a well-known online gambling platform. Analysis indicates the site was designed to deceive users into believing they were accessing legitimate Bet365 services, likely for credential theft or financial fraud. The page title, welcome-BET365, directly references the brand, reinforcing the impersonation attempt. No evidence of a crypto drainer kit or other specialized malware was observed, but the domain’s structure and content align with typical credential harvesting infrastructure. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolves to the IP address 45.196.247.179, hosted in Hong Kong under AS140224 (Nebula Global LLC), a network segment with a history of malicious activity. VirusTotal detection metrics show 21 out of 95 security vendors flagging the domain as malicious, while it appears on at least one security blocklist. Notably, the domain lacks an SSL certificate, a common red flag for fraudulent sites. Google Safe Browsing (GSB) status was not explicitly provided, but the domain’s inclusion on blocklists suggests prior detection. As of the latest assessment, m36k.xyz has been taken offline, likely due to enforcement actions by security providers or hosting interventions. The domain was blocked by PhishDestroy, indicating proactive mitigation. Despite its current offline status, residual risk remains for users who may have interacted with the domain during its active period. Organizations are advised to monitor for credential reuse attempts, particularly among users who accessed the site before takedown. Network defenders should update blocklists to include the domain and associated IP, while users should be alerted to verify URLs before entering sensitive information on gambling or financial platforms.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Intelijen Forensik
Casino / Gambling License Verification
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260211-042BA9 Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive