18075[.]xyz
“welcome-BET365”
18075.xyz — Контент недоступний. Уособлення бренду: Bet365; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 16/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLQuery 3 det.; CF Radar malicious; PhishDestroy score 98/100. Реєстратор: GMO Internet.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, 18075.xyz, is classified as a high-risk credential theft operation designed to deceive users into disclosing sensitive login credentials. Analysis indicates the infrastructure is actively targeting individuals through fraudulent login portals, likely mimicking legitimate services to exploit trust. The specific threat type—credential theft—poses significant risks, including unauthorized account access, identity fraud, and potential financial loss for victims. Infrastructure analysis reveals the domain was registered on June 28, 2026, through the registrar GMO Internet, Inc. It currently resolves to the IP address 154.39.104.132, which may host additional malicious content. The domain's SSL certificate is issued by Let's Encrypt, a common tactic to lend a false sense of legitimacy. Detection metrics further confirm its malicious nature, with 11 out of 95 security vendors on VirusTotal flagging the domain as harmful. Despite these warnings, the domain remains active, indicating ongoing or evolving malicious activity. To mitigate risks associated with credential theft, users should avoid interacting with 18075.xyz or any linked resources. Organizations are advised to block the domain and its resolving IP at the network level to prevent access. Individuals who may have entered credentials on the site should immediately reset passwords for all associated accounts, enable multi-factor authentication where available, and monitor for unauthorized activity. Security teams should review logs for connections to 154.39.104.132 or related domains to identify potential compromises. Proactive measures, such as user education on recognizing phishing attempts and implementing email filtering rules, can reduce the likelihood of successful credential theft incidents.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 1 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260701-21BFAC Recipient: abuse@internet.gmo Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога