a57a[.]xyz
“welcome-BET365”
a57a.xyz — Контент недоступен. Олицетворение бренда: Bet365; Тип мошенничества: Crypto Gambling. Сводка доказательств: VirusTotal 12/93 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 91/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain a57a.xyz was registered on 21 February 2026 and is currently taken offline. Analysis of public intelligence shows that the site presented a page titled “welcome‑BET365”, explicitly targeting the Bet365 brand and employing a crypto‑gambling lure. The SSL certificate is identified as type R12, and the domain resolves to the IPv4 address 45.196.247.146, which belongs to AS140224 (Nebula Global LLC) located in Hong Kong. VirusTotal scans have recorded 12 detections out of 93 security vendors, indicating that a notable fraction of AV engines consider the host malicious.
The domain appears on a single external blocklist and is listed as blocked by the PhishDestroy service. Additional reputation services assign extremely low scores: Gridinsoft rates the domain 0 out of 100, while Scamadviser assigns a trust score of 1 out of 100. AlienVault OTX references the domain in two separate threat‑intel pulses, reinforcing its association with known malicious campaigns. The observed attributes—brand impersonation of Bet365, crypto‑gambling context, low reputation scores, and multiple vendor detections—are consistent with a credential‑harvesting or financial‑fraud operation.
Uncertainty remains regarding the specific phishing kit or the exact payload delivered, as no page content beyond the title has been captured. Defenders should continue to block the resolved IP address and the domain on perimeter firewalls, update URL filtering feeds with the a57a.xyz indicator, and monitor for any re‑registration or resurrection of the host. Correlating the 12 vendor detections with internal logs may reveal attempted connections or credential submissions. Given the low trust scores and the presence on OTX pulses, adding the domain to internal threat‑intel repositories and sharing the indicator with upstream threat‑sharing communities is recommended.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Casino / Gambling License Verification
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание