s97j[.]xyz
“welcome-BET365”
s97j.xyz — Контент недоступний (HTTP 502). Уособлення бренду: Bet365; Тип шахрайства: Crypto Gambling. Зведення доказів: VirusTotal 11/93 (alphaMountain.ai, CRDF, CyRadar, Emsisoft, Fortinet); URLScan malicious verdict; PhishDestroy score 83/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of s97j.xyz shows that the domain was registered on 21 February 2026 and resolves to the IPv4 address 45.196.247.146, which is announced by AS140224 (Nebula Global LLC) and geolocated to Hong Kong. The TLS certificate presented is identified as R12, a short‑lived certificate commonly used by fast‑flux or malicious operators. The site title retrieved before takedown was "welcome‑BET365", and the domain is explicitly listed as impersonating the Bet365 betting brand. Threat intelligence sources classify the activity as a crypto‑gambling scam, and the domain appears on one public blocklist as well as the PhishDestroy blocklist.
AlienVault OTX records a single pulse referencing the domain, indicating limited but existing community reporting. VirusTotal scans returned detections from 11 of 93 security engines, confirming that multiple vendors consider the host malicious. The current status is offline, so no HTTP response is observed, but the historical evidence is sufficient to treat the domain as hostile. Uncertainty remains regarding the exact payload or phishing page content, as the site was taken down before a full content capture could be performed.
Defenders should immediately deny any outbound connections to 45.196.247.146, add s97j.xyz to DNS and URL filtering policies, and monitor for newly registered domains that resolve to the same ASN or share similar naming patterns. Continuous observation of Nebula Global LLC IP ranges is advised, as they have been employed in other illicit campaigns. The combination of brand impersonation, malicious certificate, multiple vendor detections, and blocklist listings warrants an elevated risk posture.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Casino / Gambling License Verification
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога