tr[.]superbetingirisim724[.]vip
“Superbetin Giriş - Superbetin Güncel Mobil Adresi | Superbetin Aktif Site Linki”
tr.superbetingirisim724.vip — Непроверенный. Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 78/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain tr.superbetingirisim724.vip is currently active and serving HTTP 200 responses. Infrastructure analysis shows the site resolves to the IPv4 address 185.192.125.120, which is geolocated to Great Britain and is hosted on Cloudflare infrastructure, as indicated by the authoritative nameservers tina.ns.cloudflare.com and kurt.ns.cloudflare.com. The TLS certificate is issued by Let’s Encrypt (identifier YE2), confirming the use of a free, publicly‑trusted certificate. Registration data reveals the domain was purchased through Dynadot Inc, a registrar frequently used by malicious operators. The page title advertises "Superbetin Giriş - Superbetin Güncel Mobil Adresi | Superbetin Aktif Site Linki," indicating a clear attempt to impersonate the Superbetin betting platform. The site is listed on one security blocklist and has been flagged by four of ninety‑one VirusTotal scanners, demonstrating a modest but non‑trivial detection rate. PhishDestroy has already added the domain to its blocklist, confirming its classification as a high‑risk phishing resource. Defenders should immediately block DNS resolution and HTTP traffic to this domain at perimeter firewalls and proxy devices. Network monitoring should be tuned to alert on any outbound connections to 185.192.125.120 or DNS queries for tr.superbetingirisim724.vip. Given the use of Cloudflare’s CDN, traditional IP‑based blocking may be less effective; therefore, domain‑level controls are recommended. Security teams should also update email gateway and anti‑phishing filters with the observed page title and the domain string to improve detection of related social‑engineering messages. Continuous re‑scanning on services such as VirusTotal is advised to track changes in detection status, and any future infrastructure shifts should be incorporated into threat intel feeds.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: superbetingirisim724.vip
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain superbetingirisim724.vip behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание