m18d[.]top
“welcome-BET365”
Сводка доказательств
The domain m18d.top was registered through NameMart Pte. Ltd. on May 15, 2026 and remains active as of the report date, July 22, 2026. Its authoritative name servers are ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, and ns4.1111343.com, and DNS resolution points to the IPv4 address 103.27.177.164. VirusTotal analysis shows that four of ninety‑five security vendors have flagged the domain, indicating a modest but notable detection rate.
The domain is listed on two external phishing blocklists, specifically PhishDestroy and OpenPhish, confirming that it is recognized by independent threat‑intelligence feeds. No additional context such as a targeted brand, page title, or SSL certificate details is available in the current intelligence set, leaving the precise phishing lure undefined. Nonetheless, the convergence of registrar information, recent creation date, dedicated name‑server infrastructure, flagged detections, and inclusion on reputable blocklists collectively point to a high‑risk generic phishing operation.
Defenders should add 103.27.177.164 to network‑level deny lists, enforce DNS blocking of m18d.top, and monitor for any traffic to the associated name servers. Continuous re‑scanning on multi‑vendor platforms is advised to capture evolving detection scores, and any future page‑content analysis should be incorporated to refine mitigation actions.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260722-5F1C30
Правовое основание
Полный текст доказательств
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | m30p.top |
phishing | Phishing Block |
| DNS4EU | m30p.top |
malicious | Sinkholed |
| DNS4EU | ssl.hw301.xyz |
malicious | Sinkholed |
| DigiCert UltraDNS | m18d.top |
malicious | Sinkholed |
| OpenDNS | m18d.top |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | m18d.top |
malicious | Sinkholed |
| Cloudflare DNS | m18d.top |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 5 технологий с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание