w22e[.]xyz
“welcome-BET365”
Kanıt özeti
The domain w22e.xyz was registered on August 15, 2025 through Gname.com Pte. Ltd. and is currently listed as offline. Technical resolution shows the domain mapped to IP address 45.196.247.191, which belongs to ASN AS140224 operated by Nebula Global LLC and is geolocated to Hong Kong. No SSL certificate was observed for the host, indicating that any communication would have occurred over clear‑text HTTP. The authoritative name servers are ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, ns4., and ns1.dnsbm.com, ns2.dnsbm.com, suggesting the use of third‑party DNS services commonly associated with malicious infrastructure. The page title returned by the site was "welcome-BET365," confirming a direct reference to the Bet365 brand.
The threat is categorized as a crypto‑gambling scam that leverages the Bet365 brand to lure victims. VirusTotal scans recorded 14 detections out of 95 security vendors, indicating that multiple anti‑malware engines identified the domain as malicious. Gridinsoft assigned a trust score of 0 out of 100, effectively flagging the site as completely untrustworthy. The domain is also listed on at least one public security blocklist and has been blocked by the PhishDestroy filtering service.
AlienVault OTX references cite the domain in 16 distinct threat‑intel pulses, reinforcing its association with ongoing malicious campaigns. While the site is presently offline, the infrastructure components—such as the Hong Kong‑based IP, the lack of TLS, and the observed name server pattern—remain reusable for future campaigns. Defenders should ensure that network perimeter controls block connections to 45.196.247.191 and any of the listed name servers, update URL filtering policies to include w22e.xyz, and monitor for any re‑registration of the domain or similar permutations.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Adli İstihbarat
Casino / Gambling License Verification
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin