j97w[.]vip
“welcome-BET365”
证据摘要
Analysis of the domain j97w.vip indicates that it is currently active and associated with a generic phishing campaign. The domain resolves to the IPv4 address 103.27.177.163, which is the sole hosting endpoint observed. DNS resolution is serviced by four name servers—ns1.1111343.com through ns4.1111343.com—suggesting a centralized infrastructure that may be leveraged for rapid redeployment. VirusTotal has recorded seven detections out of ninety‑five scanners, confirming that multiple security vendors have identified malicious behavior linked to the domain. The domain is listed on a single public blocklist and has been explicitly blocked by the PhishDestroy mitigation service, indicating that at least one specialized anti‑phishing platform has taken action against it. The threat is categorized as a generic phishing operation, and the risk rating assigned is high. No additional evidence such as SSL certificate details, HTTP response codes, or page titles has been provided, leaving those aspects of the infrastructure unverified. Defenders should continue to block traffic to the IP address 103.27.177.163 and to the domain itself at the DNS level, monitor for any changes to the name‑server configuration, and incorporate the domain into existing intrusion‑detection and web‑filtering rules. The limited blocklist presence suggests that broader detection ecosystems have not yet fully propagated the indicator, which may allow the site to reach unsuspecting users through unfiltered channels. Continuous threat‑intel sharing and timely updates to blocklists are essential to reduce exposure.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
域名情报
技术详情DNS、TLS 名称和时间戳
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控