PhishDestroy first observed j75e.vip on Jul 29, 2026. Stored content metadata identifies Bet365 as the apparent target. The captured page title is “welcome-BET365”. Page analysis recorded additional brand references to Gmail. Stored page analysis classifies the content as impersonation. Current evidence score: 100/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and Spamhaus DBL. VirusTotal recorded 17 detections among 91 engines: alphaMountain.ai, BitDefender, Cluster25, CRDF, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, MalwareURL, SOCRadar, Sophos, VIPRE, Webroot on Aug 6, 2026 at 02:22 UTC. Spamhaus DBL: DBL_SPAM on Jul 29, 2026 at 14:30 UTC. Non-positive and contextual checks: The separate external-blocklist snapshot contained no matches on Aug 8, 2026 at 10:20 UTC. Google Safe Browsing returned no flag on Jul 29, 2026 at 12:58 UTC. URLScan completed without a malicious verdict (score 0) on Aug 1, 2026 at 03:30 UTC.
HTTP 200 was recorded on Aug 8, 2026 at 10:30 UTC. At collection time, the hostname resolved to 103.244.148.114 on AS135357 (HONG KONG KOWLOON TELECOMMUNICATIONS CO.,LIMITED). The recorded endpoint location is Hong Kong, HK. The stored server header is Nginx. DOM analysis on Jul 29, 2026 at 14:20 UTC returned 78/100. The evidence archive retains 3 visual captures from PhishDestroy and URLScan. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Sep 12, 2026; checked Jul 29, 2026 at 13:02 UTC.
The content indicators and 2 positive source findings support the current Bet365-themed impersonation classification.