j105p[.]vip
“welcome-BET365”
j105p.vip — Неперевірений. Уособлення бренду: Bet365; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 21/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLScan malicious verdict; Spamhaus DBL_SPAM; PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
j105p.vip is currently listed as an active generic phishing infrastructure. VirusTotal records show that 17 of 91 scanning engines have flagged the domain, indicating a majority of security products recognize malicious activity associated with it. The domain resolves to the IPv4 address 103.27.177.164 and is served by four authoritative name servers (ns1-4.1111343.com), a pattern observed in other malicious deployments that use the same registrar. AlienVault OTX includes the domain in a single threat‑intelligence pulse, and it appears on one public blocklist; PhishDestroy explicitly blocks it, confirming that at least one anti‑phishing feed is actively preventing access. No additional public indicators such as SSL certificates, HTTP status codes, or Safe Browsing reputation scores are provided in the current intelligence set, leaving those aspects unverified. The limited data set means that the exact content and targeted brand of the phishing page remain unknown, and no page‑title or credential‑capture details have been disclosed. Defenders should add 103.27.177.164 to network‑level deny lists and configure DNS filtering to block any resolution of j105p.vip. Monitoring of outbound traffic for connections to the identified name servers and the IP address is recommended, as is periodic re‑query of VirusTotal and OTX for updates to detection counts. Organizations employing email security gateways should ensure that signatures derived from the 17 VT detections are deployed, and endpoint protection solutions should be instructed to quarantine any files flagged by the same scanners. Continuous observation of blocklist changes will help maintain coverage as the threat actor potentially expands its infrastructure.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% впевненостіNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога