The domain jojobet5444.com hosted on IP address 204.76.203.30 is a phishing clone of our legitimate ...
show moreThe domain jojobet5444.com hosted on IP address 204.76.203.30 is a phishing clone of our legitimate site jojobet1021.com. It mimics our branding and login interface to steal user credentials and hijack user accounts. The phishing site lacks our official footer elements such as the GCB license link and 18+ logo, clearly indicating malicious intent.
We request that appropriate action be taken against this IP due to its involvement in credential theft and fraud.
show less
The domain holiganbet5962.com hosted at this IP is a phishing clone of our official site holiganbet1 ...
show moreThe domain holiganbet5962.com hosted at this IP is a phishing clone of our official site holiganbet1092.com. It mimics our interface to steal user credentials and fraudulently access real accounts. Key differences include missing GCB license links and 18+ warnings in the footer. This domain is actively deceiving users and facilitating financial fraud.
show less
This IP address (95.129.234.10) is hosting a phishing website located at https://holiganbet5784.com. ...
show moreThis IP address (95.129.234.10) is hosting a phishing website located at https://holiganbet5784.com.
The site is a malicious clone of our official domain (https://www.holiganbet1092.com/tr/sports/i/) and is being used to harvest customer login credentials. Users who enter their usernames and passwords on the phishing site are later compromised, with their data being used to access their real accounts.
Clear Indicators of Phishing:
Identical design and structure to the original website
Missing our official GCB license link in the footer
No Live Chat function
No "18+" responsible gaming notice
This phishing site directly violates cybersecurity laws and puts our users at financial and data risk.
We respectfully request that you take immediate action against this abusive IP.
show less
This IP is hosting a phishing website: https://holigonbet1054.com
It is a clone of our legitimate p ...
show moreThis IP is hosting a phishing website: https://holigonbet1054.com
It is a clone of our legitimate platform https://www.holiganbet1092.com/tr/sports/i/ and is used to deceive our customers into entering their credentials.
Once credentials are stolen, attackers log in to our real site and transfer user funds.
Key differences:
The phishing site lacks the GCB license link in the footer
The “18+” warning logo is also missing
This is a serious security threat to our users. Please take urgent action.
show less
I am reporting a serious phishing operation and brand abuse targeting our company and endangering ou ...
show moreI am reporting a serious phishing operation and brand abuse targeting our company and endangering our users' security.
Involved Domains:
Redirect source (via hacklinks on Google): https://goldenbahis-check.vip/
Phishing destination: https://goldenbahisl788.com/
Official and legitimate website: https://goldenbahis790.com/tr
Summary of Abuse:
The domain goldenbahis-check.vip has been artificially ranked on Google’s first page through illicit SEO practices (likely hacklink injections).
When users click this link, they are silently redirected to goldenbahisl788.com, a phishing clone of our legitimate website.
This fake site imitates our entire layout, design, and branding, including the use of our “Goldenbahis” name and logo without permission, in order to deceive visitors.
Once the users enter their credentials, attackers gain unauthorized access to their accounts and transfer funds from victim wallets.
show less
I am reporting a serious phishing operation and brand abuse targeting our company and endangering ou ...
show moreI am reporting a serious phishing operation and brand abuse targeting our company and endangering our users' security.
Involved Domains:
Redirect source (via hacklinks on Google): https://goldenbahis-check.vip/
Phishing destination: https://goldenbahisl788.com/
Official and legitimate website: https://goldenbahis790.com/tr
Summary of Abuse:
The domain goldenbahis-check.vip has been artificially ranked on Google’s first page through illicit SEO practices (likely hacklink injections).
When users click this link, they are silently redirected to goldenbahisl788.com, a phishing clone of our legitimate website.
This fake site imitates our entire layout, design, and branding, including the use of our “Goldenbahis” name and logo without permission, in order to deceive visitors.
Once the users enter their credentials, attackers gain unauthorized access to their accounts and transfer funds from victim wallets.
show less
I am writing to formally report a phishing website that is impersonating our legitimate brand, NEROB ...
show moreI am writing to formally report a phishing website that is impersonating our legitimate brand, NEROBET, with the clear intent to deceive our customers and steal their account credentials and funds.
The infringing website is:
🔗 https://mobille-nerobet520.casino/m/
This domain is a clone of our official platform:
🔗 https://nerobet520.com/tr
The malicious actors behind the clone have replicated our entire user interface, design, and copyrighted content. Most critically, they are using the NEROBET trademark name and logo without authorization.
show less
I am writing to formally report a phishing website that is abusing our trademarked brand name BETASU ...
show moreI am writing to formally report a phishing website that is abusing our trademarked brand name BETASUS and compromising the security of our users. The domain in question, https://betasusl003.com, is a fraudulent copy of our official platform and is being used for credential harvesting and unauthorized access to user accounts.
Details of the Abuse:
Phishing Activity: The site is a direct clone of our official website, https://www.betasus1003.com/tr/. Users are tricked into entering their login credentials, which are then used to log into our real platform and illegally withdraw funds from user accounts.
Visual and Functional Cloning: The entire website—including layout, design, brand assets, and user interface—has been copied without authorization.
Typographical Deception: The attackers use a visual spoofing tactic by substituting the number "1" with a capital "I" in the domain name, making it look nearly identical to our official URL to mislead users (e.g., "betasusI003" instead of "betasus1003").
show less
I am writing to report a dangerous phishing website that is actively impersonating our legitimate br ...
show moreI am writing to report a dangerous phishing website that is actively impersonating our legitimate brand and putting users at significant risk.
Malicious Domain: https://betasusl002.com
Official Website: https://www.betasus1002.com/tr/
Affected Brand: Betasus
The phishing site is an unauthorized exact replica of our legitimate platform and is promoted via unethical SEO methods, including hacklink placements from domains such as https://betasus-girisi.com/. Its sole purpose is to harvest login credentials and illegally access user accounts to steal funds.
One key indicator of its malicious intent is found in the footer section: the so-called “Curacao license” link is fraudulent—it does not lead to a legitimate licensing authority, but instead reloads the same phishing website. This is clearly a tactic to deceive users into believing the site is officially regulated.
show less
am writing to report a dangerous phishing website that is actively impersonating our legitimate bran ...
show moream writing to report a dangerous phishing website that is actively impersonating our legitimate brand and putting users at significant risk.
Malicious Domain: https://betasusl002.com
Official Website: https://www.betasus1002.com/tr/
Affected Brand: Betasus
The phishing site is an unauthorized exact replica of our legitimate platform and is promoted via unethical SEO methods, including hacklink placements from domains such as https://betasus-girisi.com/. Its sole purpose is to harvest login credentials and illegally access user accounts to steal funds.
One key indicator of its malicious intent is found in the footer section: the so-called “Curacao license” link is fraudulent—it does not lead to a legitimate licensing authority, but instead reloads the same phishing website. This is clearly a tactic to deceive users into believing the site is officially regulated.
show less
Dear ICANN Compliance Team,
We wish to formally report NICENIC International Group Co., Ltd. (IAN ...
show moreDear ICANN Compliance Team,
We wish to formally report NICENIC International Group Co., Ltd. (IANA ID: 3765) for failing to take action against a domain facilitating phishing and trademark infringement: https://holigonbet1052.com.
Offending Domain: https://holigonbet1052.com
Hosting IP: 185.208.156.26
Our Official Platform: https://www.holiganbet1090.com
Registered Trademark: HOLIGANBET (UK00003544293)
Trademark Record: UK IPO Link
Reporter: Ufuk Omur – [email protected]
The domain replicates our platform and illegally harvests user data to access legitimate accounts and commit financial theft.
A key detail exposing the site’s fraudulent nature: the absence of the GCB license badge in the page footer, which is always present on our real site.
Despite our notice to NICENIC, no adequate action has been taken. This is a breach of:
ICANN RAA §3.18
UDRP policies
show less
We report the domain https://jojobelt1018.com, hosted by your company, for serious abuse involving p ...
show moreWe report the domain https://jojobelt1018.com, hosted by your company, for serious abuse involving phishing and impersonation of our official platform.
Phishing Domain: https://jojobelt1018.com
Hosting IP: 62.182.85.168
Legitimate Site: https://www.jojobet1019.com
Registered Trademark: JOJOBET (UK00003430378)
This fraudulent domain is a pixel-perfect clone of our official platform and is used to harvest user credentials, enabling unauthorized access to accounts and illegal fund transfers.
Notably, the phishing site omits the GCB license information in its footer – a hallmark of our platform’s legitimacy. This absence is a critical differentiator confirming its fraudulent nature.
Please take immediate action to suspend the associated hosting account and stop the ongoing abuse.
Sincerely
show less
We wish to report the domain https://jojobeet1018.com, hosted on your network, which is actively bei ...
show moreWe wish to report the domain https://jojobeet1018.com, hosted on your network, which is actively being used in a phishing scheme targeting our users and brand.
Offending Domain: https://jojobeet1018.com
Redirects To: https://www.jojobet1019.com (confirmed phishing domain)
Our Official Brand: https://www.jojobet1019.com
Trademark: JOJOBET (UK00003430378)
IP Address: 193.27.90.102
This site is being used as a redirect trap, tricking users into believing they are visiting a legitimate site before being silently redirected to a fraudulent clone of our official website. The redirect occurs immediately upon page load.
This tactic violates:
Your terms of service regarding malicious activity
Anti-phishing and consumer deception laws
Trademark protections and intellectual property rights
We request you to take down the domain jojobeet1018.com and suspend any associated accounts.
Sincerely
show less
We are writing to formally lodge a complaint regarding the domain https://jojobet5113.com, which is ...
show moreWe are writing to formally lodge a complaint regarding the domain https://jojobet5113.com, which is registered through your services and is actively engaging in phishing and trademark infringement. This fraudulent website is a pixel-perfect clone of our official website (https://www.jojobet1019.com), and is being used to deceive our users, steal login credentials, and unlawfully access accounts to transfer funds.
This constitutes a clear violation of intellectual property rights under international trademark laws and contravenes provisions under:
The Uniform Domain Name Dispute Resolution Policy (UDRP)
ICANN’s Registrar Accreditation Agreement (RAA) – Section 3.18 (Registrar Abuse Contact)
Anti-Phishing and Consumer Protection Laws applicable in several jurisdictions
We request immediate action under your responsibilities as a domain registrar to:
Suspend or remove the domain jojobet5113.com
show less
We would like to urgently report a phishing website that is impersonating our official platform and ...
show moreWe would like to urgently report a phishing website that is impersonating our official platform and deceiving our users:
Official Website: https://www.holiganbet1090.com/tr/sports/i/
Phishing Website (Clone): https://m-holiganbet1092.com/
Redirect Link Used in Campaigns: https://tr-holigan-girisleri.vip/
IP Address: 95.129.234.157
Hosting Provider: DDOS-GUARD
Domain Registrar: NICENIC
The phishing site is a complete replica of our original website, "holiganbet", and is being used to deceive our users. When users search for our brand, they are misled via https://tr-holigan-girisleri.vip/ to the fake website where they are prompted to enter their login credentials.
Once entered, these credentials are used by attackers to access users’ real accounts on our original website and withdraw funds from their balances into unauthorized accounts.
show less
I am writing to urgently report a phishing website that is actively impersonating our official platf ...
show moreI am writing to urgently report a phishing website that is actively impersonating our official platform and abusing Cloudflare’s services. The domain in question is:
https://pulibet829.com/m/
This website is a fraudulent replica of our official website:
https://pulibet729.com/
The phishing domain mimics our platform’s design and functionality in full detail, with the intention of deceiving users into entering their usernames and passwords. These stolen credentials are then used to log in to our legitimate website and illegally transfer funds from user accounts.
One clear distinguishing factor between the phishing domain and our legitimate website is the absence of our official green GCB license badge, which is prominently displayed on our homepage. This badge is a verified proof of our licensing and compliance, and its absence helps confirm that the site is fraudulent.
show less
I am writing to urgently report a phishing website that is actively impersonating our official platf ...
show moreI am writing to urgently report a phishing website that is actively impersonating our official platform and abusing Cloudflare’s services. The domain in question is:
https://pulibet829.com/m/
This website is a fraudulent replica of our official website:
https://pulibet729.com/
The phishing domain mimics our platform’s design and functionality in full detail, with the intention of deceiving users into entering their usernames and passwords. These stolen credentials are then used to log in to our legitimate website and illegally transfer funds from user accounts.
One clear distinguishing factor between the phishing domain and our legitimate website is the absence of our official green GCB license badge, which is prominently displayed on our homepage. This badge is a verified proof of our licensing and compliance, and its absence helps confirm that the site is fraudulent.
show less
Dear AbuseIPDB Team,
We would like to report the domain https://goldenbahis7934.com as a phishing ...
show moreDear AbuseIPDB Team,
We would like to report the domain https://goldenbahis7934.com as a phishing website. It is impersonating our official site, https://goldenbahis786.com/tr, by replicating it entirely — design, content, and user interface.
This site is tricking users into entering their login credentials, which are then exploited to access the legitimate platform and fraudulently transfer funds from victims' accounts.
Furthermore, it falsely displays a licensing badge ("Antillephone License Validation") that leads to an error page, indicating fake compliance credentials.
show less
Dear Abuse Team,
We are writing to formally report a phishing website hosted on your infrastructu ...
show moreDear Abuse Team,
We are writing to formally report a phishing website hosted on your infrastructure that is impersonating our legitimate brand and is actively stealing user credentials.
Details of the infringing site:
Phishing Domain: https://www.holiganbett1089.com/tr/ios-app
IP Address: 38.180.112.52
Original Website Being Imitated: https://www.holiganbet1088.com/
The site in question is a direct clone of our official platform and is being used for phishing purposes. Users who enter their credentials on the fraudulent site have had their login information stolen and their accounts compromised, resulting in financial theft.
We request the immediate suspension of hosting services for the domain holiganbett1089.com in accordance with your Terms of Service and applicable laws related to phishing and online fraud.
We would appreciate a prompt response and confirmation that appropriate action has been taken.
Sincerely
show less
We, the Holiganbet Legal Team, are submitting an urgent abuse complaint regarding two fraudulent dom ...
show moreWe, the Holiganbet Legal Team, are submitting an urgent abuse complaint regarding two fraudulent domains registered under your service:
https://holigan-girisi.vip/ – This domain is manipulating Google search rankings using black-hat SEO techniques (hacklink injection) to appear in top search results for our trademarked brand name, "Holiganbet." It then redirects visitors based on their device type.
https://holigonbet1044.com/ – This is a one-to-one phishing replica of our legitimate platform, https://www.holiganbet1088.com/tr/sports/i/, used for credential theft and financial fraud.
show less
We are submitting a formal complaint regarding Global-Data System IT Corporation (AS42624) for its c ...
show moreWe are submitting a formal complaint regarding Global-Data System IT Corporation (AS42624) for its continued facilitation of phishing and financial fraud through its Switzerland-based infrastructure.
I have identified a sophisticated Conditional Phishing technique being used by fraudulent websites.
Phishing Entry Points (Google SEO Manipulation):
The following domains manipulate Google search rankings and redirect users to phishing sites:
https://jojobete-girisi.com/ → IP: 185.208.156.28
https://tr-jojobet-adresi.com/ → IP: 185.208.156.26
https://tr-holiganbet-giris.com/ → IP: 185.208.156.27
Phishing Destination Sites (Fake Betting Platforms):
Once redirected, users land on these phishing sites:
https://jojobet5106.com/ → IP: 185.208.156.28
https://jojobett10116.com/ → IP: 95.129.234.27
https://jojobet5614.com/ → IP: 185.149.120.17
https://holigonbet1047.com/ → IP: 185.208.156.26
Backup Phishing Domains:
They also use alternative domains to maintain search ranking manipulation:
show less
jojobet5475.com is a phishing website impersonating our official platform jojobet1015.com to steal u ...
show morejojobet5475.com is a phishing website impersonating our official platform jojobet1015.com to steal user credentials. Victims unknowingly enter their login details, which are then used to access real accounts and withdraw funds fraudulently. The fake site lacks our GCB license and live chat. This scam violates security policies and endangers users. We request urgent action to investigate and take it down.
show less
I am reporting a phishing website that is impersonating our official platform and stealing user cred ...
show moreI am reporting a phishing website that is impersonating our official platform and stealing user credentials. The fraudulent website jojobet5109.com is a direct copy of our legitimate website jojobet1015.com and is used to harvest usernames and passwords.
🚨 Phishing Website: https://jojobet5109.com/
✅ Official Website: https://www.jojobet1015.com/tr/sports/i/
🔴 Evidence of Phishing and Fraudulent Activity:
Credential Theft: Users who enter their login details on jojobet5109.com have their credentials stolen and misused.
Financial Fraud: Stolen credentials are used to access the official site and withdraw funds from user accounts.
Incomplete Replication: The fake site lacks our GCB license verification, and live chat features do not function.
This site violates Google’s Safe Browsing policies and poses a severe security risk to users. We kindly request an urgent review and blacklisting of jojobet5109.com from Google Search and Chrome’s Safe Browsing warnings.
show less
Dear AbuseIPDB Team,
We would like to report multiple IP addresses actively engaging in phishing ...
show moreDear AbuseIPDB Team,
We would like to report multiple IP addresses actively engaging in phishing and financial fraud by hosting websites that impersonate our legitimate platform. These fraudulent websites steal user credentials and facilitate unauthorized transactions.
Details of the Malicious IPs & Websites:
IP Address: 195.211.191.145
Fraudulent Websites:
http://holiganbet5955.com/
https://holiganbet2344.com/
Legitimate Website Being Impersonated: https://www.holiganbet1087.com/tr/sports/i/
Nature of Abuse:
Hosting phishing pages that mirror our official website.
Engaging in credential theft and unauthorized fund transfers.
Violating cybersecurity laws and AbuseIPDB policies.
Requested Actions:
Immediate listing of the reported IP in AbuseIPDB’s database to warn other users and prevent further abuse.
Investigation and escalation to relevant cybersecurity authorities if necessary.
show less
Phishing
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.