x112c[.]xyz
“welcome-BET365”
x112c.xyz — 内容不可用 (HTTP 502). 品牌冒充:Bet365. 证据摘要: VirusTotal 23/94 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 6 alerts; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, x112c.xyz, is identified as a credential theft operation designed to harvest usernames, passwords, and other sensitive information from unsuspecting visitors. Unlike generic phishing pages, credential theft sites often mimic login portals of legitimate services, tricking users into submitting their credentials directly to attackers. The stolen data is frequently used for unauthorized account access, financial fraud, or sold on dark web marketplaces. Users may encounter this domain through malicious links in emails, social media messages, or compromised advertisements, making vigilance critical when interacting with unfamiliar URLs. Analysis of x112c.xyz reveals multiple high-confidence indicators of malicious activity. The domain was registered on March 27, 2026, through Gname.com Pte. Ltd., an uncommon choice for legitimate services, and resolves to the IP address 45.196.247.179, hosted in Hong Kong under Nebula Global LLC. Security vendors on VirusTotal flagged the domain as malicious, with 23 out of 95 engines detecting it as a threat. Additionally, Google Safe Browsing has explicitly classified it as a phishing site, and it appears on at least one security blocklist, further corroborating its fraudulent nature. The SSL certificate, issued by Let's Encrypt (R13), provides encryption but does not validate the site's legitimacy, as attackers frequently use free certificates to appear trustworthy. If you visited x112c.xyz or entered any information on the site, immediate action is required to mitigate potential damage. First, disconnect the affected device from the internet to prevent further data exfiltration. Change passwords for any accounts accessed or entered on the site, prioritizing email, banking, and social media platforms. Enable multi-factor authentication (MFA) wherever possible to add an extra layer of security. Scan the device using reputable security software to detect and remove any malware or spyware that may have been installed. Monitor financial statements and account activity for unauthorized transactions, and report any suspicious activity to the relevant service providers. Finally, consider notifying local cybersecurity authorities or organizations that track fraudulent domains to help prevent further victimization.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | x112c.xyz |
malicious | Sinkholed |
| DNS4EU | x112c.xyz |
malicious | Sinkholed |
| Cloudflare DNS | x112c.xyz |
malicious | Sinkholed |
| OpenDNS | x112c.xyz |
phishing | Phishing Block |
| Hagezi Threat Feed | img.esportsdata.cc |
malicious | Sinkholed |
| DNS4EU | img.esportsdata.cc |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
PD-20260327-D067BF Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。