j168r.vip
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of j168r.vip
j168r.vip appears to be a gambling-related login portal, likely aimed at Chinese-speaking users. The page title references "BET365," and the screenshot shows a casino-style background with a username/password form, suggesting the site may be presenting itself as an online betting or gaming access page rather than a general informational website.
Based on the domain name, page layout, and linked resources, this does not appear to be a broad corporate website or a well-established consumer service. The site seems focused on account sign-in, with little visible company identification, ownership transparency, or supporting business information on the landing page. That combination can be consistent with a private betting portal, an affiliate-style gateway, or a look-alike login page.
No clear operator identity is provided in the scan data. The domain is very new and uses a generic-looking .vip address rather than an obvious official brand domain, which may make independent verification more difficult.
Safety Assessment for j168r.vip
The scan results indicate elevated risk at the time of analysis. The domain was flagged by 14 out of 91 security engines, with many of those detections classifying it as phishing. In addition, the page title references a well-known betting brand while using a different domain name, and the site presents a credential-entry form. That resemblance may indicate the site is attempting to look associated with a recognized gambling platform when it may not be.
The domain is only 6 days old, has no established traffic ranking in the provided data, and exposes a minimal login-focused interface with limited ownership or trust information. A malware scan also marked 11 JavaScript files as suspicious, although those findings were generic heuristic detections rather than named malware families. Separately, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds some caution.
Taken together, the multi-engine phishing detections, very recent registration, brand-referencing page title, and credential-harvesting appearance are meaningful warning signs. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring on 2026-11-23 and is served over Nginx from an IP hosted by StarCloudGlobal-HK in Hong Kong. A valid certificate helps encrypt traffic in transit, but it does not by itself verify that the operator is trustworthy. The domain uses four nameservers under 1111343.com and does not appear to have DNSSEC enabled.
From a security perspective, the most notable concerns are the domain's very recent creation date, unsigned DNSSEC status, and the presence of multiple JavaScript files flagged as suspicious by heuristic scanning. The page also loads configuration scripts related to messaging and verification components, which is not inherently malicious but may warrant additional scrutiny in the context of a newly registered login portal.
Share your experience with this website. Was it safe? Did you encounter any issues?