w22e[.]xyz
“welcome-BET365”
Сводка доказательств
The domain w22e.xyz was registered on August 15, 2025 through Gname.com Pte. Ltd. and is currently listed as offline. Technical resolution shows the domain mapped to IP address 45.196.247.191, which belongs to ASN AS140224 operated by Nebula Global LLC and is geolocated to Hong Kong. No SSL certificate was observed for the host, indicating that any communication would have occurred over clear‑text HTTP. The authoritative name servers are ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, ns4., and ns1.dnsbm.com, ns2.dnsbm.com, suggesting the use of third‑party DNS services commonly associated with malicious infrastructure. The page title returned by the site was "welcome-BET365," confirming a direct reference to the Bet365 brand.
The threat is categorized as a crypto‑gambling scam that leverages the Bet365 brand to lure victims. VirusTotal scans recorded 14 detections out of 95 security vendors, indicating that multiple anti‑malware engines identified the domain as malicious. Gridinsoft assigned a trust score of 0 out of 100, effectively flagging the site as completely untrustworthy. The domain is also listed on at least one public security blocklist and has been blocked by the PhishDestroy filtering service.
AlienVault OTX references cite the domain in 16 distinct threat‑intel pulses, reinforcing its association with ongoing malicious campaigns. While the site is presently offline, the infrastructure components—such as the Hong Kong‑based IP, the lack of TLS, and the observed name server pattern—remain reusable for future campaigns. Defenders should ensure that network perimeter controls block connections to 45.196.247.191 and any of the listed name servers, update URL filtering policies to include w22e.xyz, and monitor for any re‑registration of the domain or similar permutations.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Casino / Gambling License Verification
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание