84698[.]xyz
“welcome-BET365”
Сводка доказательств
On 23 July 2026 the domain 84698.xyz was observed as an offline infrastructure used to impersonate Bet365. The domain was registered on 7 January 2026 through Gname.com Pte. Ltd. and resolves to the IPv4 address 45.196.247.189, which is announced by AS140224 (Nebula Global LLC) and geolocated to Hong Kong. The host presents an SSL certificate identified as R13, indicating the use of a low‑trust certificate. The HTTP response previously returned a page whose title was “welcome‑BET365”, matching the declared brand target Bet365 and the scam type “Crypto Gambling”.
Reputation checks show a Gridinsoft trust score of 0 / 100 and detection by 14 of 93 VirusTotal scanners. The domain appears on a single security blocklist and has been blocked by the PhishDestroy service. AlienVault OTX references the domain in two separate threat‑intel pulses, further confirming its malicious use. The combination of a fresh registration, low trust score, hostile SSL, and multiple vendor detections suggests a purpose‑built phishing or crypto‑gambling lure aimed at Bet365 customers.
No public evidence of the page content, login fields, or payload has been released, so the exact phishing kit or credential‑harvesting technique remains unknown. Analysts should continue to monitor the IP address 45.196.247.189 for any re‑activation, enforce blocklists that include 84698.xyz, and consider adding the ASN or host to network‑level deny lists. Additional scrutiny of other domains registered by the same registrar during the same period may reveal related infrastructure. Defenders are advised to educate Bet365 users about unsolicited links that reference “welcome‑BET365” and to verify TLS certificates before entering credentials.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | 84698.xyz |
malicious | Sinkholed |
| OpenDNS | 84698.xyz |
phishing | Phishing Block |
| Cloudflare DNS | 84698.xyz |
malicious | Sinkholed |
| DNS4EU | 84698.xyz |
malicious | Sinkholed |
| Hagezi Threat Feed | 84698.xyz |
malicious | Sinkholed |
| Quad9 DNS | 84663.xyz |
malicious | Sinkholed |
| DNS4EU | ssl.gfw301.top |
malicious | Sinkholed |
| DNS0 Zero | ssl.gfw301.top |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание