p208a[.]xyz
“welcome-BET365”
p208a.xyz — Контент недоступен. Олицетворение бренда: Google; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 19/94 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, Cluster25, CRDF); URLQuery 3 alerts; CF Radar malicious; PhishDestroy score 100/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On July 23, 2026, the domain p208a.xyz was observed in an elevated‑risk brand‑impersonation campaign targeting Google credentials. The site’s HTML title is “welcome‑BET365”, which does not reference the intended victim brand, suggesting a reused template. The domain resolves to IP 45.196.247.26, an address registered to Nebula Global LLC in Hong Kong (AS140224). No TLS certificate was presented; attempts to establish an HTTPS connection fail, yet the HTTP response includes an HSTS header, indicating that the operator may have configured HSTS without a valid certificate. The web server identified by the response headers is Nginx serving a Vue.js application, a stack commonly used in commodity phishing kits.
The domain was registered on March 09 2026 through Gname.com Pte. Ltd., and its authoritative name servers are ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, ns1.dnsbm.com, ns2.dnsbm.com, and ns4. The registrar and name‑server pattern match other known malicious infrastructures used in credential‑phishing operations. Reputation services flag the site as extremely untrustworthy: Gridinsoft assigns a score of 0 / 100, Scamadviser a score of 1 / 100, and the domain appears on a single security blocklist. VirusTotal analysis shows that 19 of 94 scanned engines raise a detection, confirming malicious classification. PhishDestroy has already taken the domain offline, and the current status is reported as “taken offline”.
Evidence confirms the campaign’s objective is credential harvesting against Google accounts, though the exact phishing page content has not been captured. The lack of SSL, combined with the presence of HSTS, suggests a hurried deployment that may be abandoned or moved to a new infrastructure. Defenders should block the domain and its resolved IP at network perimeter devices, update URL filtering feeds with the domain and associated name servers, and monitor for similar name‑server or IP patterns.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | p208a.xyz |
malicious | Sinkholed |
| Hagezi Threat Feed | img.esportsdata.cc |
malicious | Sinkholed |
| DNS4EU | img.esportsdata.cc |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Технологии · 3 identified
Progressive JavaScript framework for building user interfaces.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260315-E3C665 Recipient: complaint@gname.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание