MALICIOUS — CRITICAL
kelabet[.]com
Analysis on kelabet.com shows it was registered on November 6, 2025 through Dominet (HK) Limited and resolved to the IP address 188.114.97.3, which is owned by AS13335 Cloudflare, Inc.
- VirusTotal
- 11/95
- Blocklists
- No stored match
- 可用性
- 内容不可用 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
kelabet.com — 内容不可用 (HTTP 502). 品牌冒充:Genericcrypto; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 11/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. 注册商: Dominet (HK).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
Analysis on kelabet.com shows it was registered on November 6, 2025 through Dominet (HK) Limited and resolved to the IP address 188.114.97.3, which is owned by AS13335 Cloudflare, Inc. in the United States. The domain is listed on a single security blocklist and has been blocked by PhishDestroy, indicating that it was previously identified as a phishing source. VirusTotal reports that 11 of 95 scanned security vendors flagged the domain as malicious, providing additional corroboration of its threat status.
The page title returned by the server, "Kelabet: Most Popular Online Crypto Casino Based on Blockchain," aligns with the reported scam type of a crypto‑related gambling scheme, and the associated phishing kit is labeled "Gambler Scam." Gridinsoft assigned a trust score of 1 out of 100, further confirming the low reputation of the site. No SSL certificate was observed, meaning traffic to the site was unencrypted, which is typical for many fraudulent deployments. Nameservers davina.ns.cloudflare.com and hank.ns.cloudflare.com confirm that the domain relied on Cloudflare’s DNS infrastructure.
The current offline status suggests that the site has been taken down, but the historical indicators remain relevant for threat‑intel correlation and for preventing future re‑use of the same infrastructure. Defenders should continue to block the domain at perimeter defenses, monitor the associated IP range for any resurgence of malicious activity, and add the domain to internal watchlists. Additional investigation of the Gambler Scam kit may reveal reusable components that could appear in other campaigns, and analysts should verify whether any related domains share the same registrar or nameserver configuration.
数据覆盖范围13 recorded checks
安全信号
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
VirusTotal 分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。