Hostname
bet98d.com
Last fetched
bet98d.com resolves to 103.194.105.19, announced in 103.194.105.0/24 by ANTBOX1-AS-AP - Antbox Networks Limited in HK. bet98d.com is listed by 2 threat feeds; reconciled level LOW.
Threat posture
1threat score (procedure-native scale)
LOWListed by 2 threat feeds.
- Threat feeds listing this
- 2
- Verdict coverage
- malicious-evidenced
- First seen on a feed
- Wed, 26 Aug 2026 14:45:21 GMT
- Last seen on a feed
- Fri, 09 Oct 2026 23:53:34 GMT
Nutrition Label
Resolution chain
- 103.194.105.19
103.194.105.0/24 · ANTBOX1-AS-AP - Antbox Networks Limited · Mid Levels, HK
- 103.194.105.190
103.194.105.0/24 · ANTBOX1-AS-AP - Antbox Networks Limited · Mid Levels, HK
- 103.194.105.191
103.194.105.0/24 · ANTBOX1-AS-AP - Antbox Networks Limited · Mid Levels, HK
- 103.194.184.74
- 116.204.177.144
116.204.177.0/24 · ANTBOX1-AS-AP - Antbox Networks Limited · Mid Levels, HK
- 116.204.178.12
116.204.178.0/24 · ANTBOX1-AS-AP - Antbox Networks Limited · Mid Levels, HK
- 116.204.178.6
116.204.178.0/24 · ANTBOX1-AS-AP - Antbox Networks Limited · Mid Levels, HK
- 116.213.38.210
116.213.38.0/24 · NETSEC-HK - Netsec Limited · San Po Kong, HK
- 180.178.39.179
180.178.39.0/24 · NETSEC-HK - Netsec Limited · Lai Chi Kok, HK
- 182.16.3.82
182.16.3.0/24 · NETSEC-HK - Netsec Limited · Lai Chi Kok, HK
- 91.195.240.94
- 180.178.39.180
180.178.39.0/24 · NETSEC-HK - Netsec Limited · Lai Chi Kok, HK
- 182.16.3.83
182.16.3.0/24 · NETSEC-HK - Netsec Limited · Lai Chi Kok, HK
- 103.194.105.22
103.194.105.0/24 · ANTBOX1-AS-AP - Antbox Networks Limited · Mid Levels, HK
- 116.213.36.226
116.213.36.0/24 · NETSEC-HK - Netsec Limited · San Po Kong, HK
- 116.213.38.212
116.213.38.0/24 · NETSEC-HK - Netsec Limited · San Po Kong, HK
IPv6 resolution
No AAAA record for bet98d.com is recorded in WhisperGraph.
Attribution
antbox
ORIGIN_AS
WHOIS identity
- Registrar
- iana:625
- Registrant organisation
- 金 何
Subdomains
| Subdomain |
|---|
| www.bet98d.com |
Showing 1 of 1 subdomain (1 per page).
Mail and authentication
DNSSEC
WhisperGraph records no DNSSEC signature for bet98d.com.
DKIM signing
No DKIM signing vendor is attributed to bet98d.com in WhisperGraph.
DNS signals
- The zone's primary nameserver (its SOA record) is not among its published nameservers.
Nameservers
- julio.ns.cloudflare.com
- lilith.ns.cloudflare.com
- ns1cnb.name.com
- ns2fgv.name.com
- ns3cna.name.com
- ns4lqx.name.com
- a.gtld-servers.net
- b.gtld-servers.net
- c.gtld-servers.net
- d.gtld-servers.net
- e.gtld-servers.net
- f.gtld-servers.net
- g.gtld-servers.net
- h.gtld-servers.net
- i.gtld-servers.net
- j.gtld-servers.net
- k.gtld-servers.net
- l.gtld-servers.net
- m.gtld-servers.net
MX records
- mail.pickelhost.com
Threat-feed evidence
History
Related pages
Pivot from bet98d.com into the addresses, networks and registries it depends on.
Queries
This hostname's full card — resolution chain, registration, mail policy, DNSSEC and mail authentication.
MATCH (h:HOSTNAME {name: $host})
OPTIONAL MATCH (h)-[:RESOLVES_TO]->(ip:IPV4)-[:ANNOUNCED_BY]->(ap:ANNOUNCED_PREFIX)
OPTIONAL MATCH (a:ASN)-[:ROUTES]->(ap)
OPTIONAL MATCH (a)-[:HAS_NAME]->(an:ASN_NAME)
OPTIONAL MATCH (ip)-[:LOCATED_IN]->(city:CITY)
OPTIONAL MATCH (ip)-[:HAS_COUNTRY]->(ipc:COUNTRY)
WITH h, ip, ap, a, an, city, ipc
LIMIT 20
WITH h,
collect({ip: ip.name, prefix: ap.name, asn: a.name, network: an.name, city: city.name, country: ipc.name}) AS resolutions,
collect(a.name) AS asnNames,
collect(ap.name) AS prefixNames,
collect(ap.isMoas) AS moasFlags,
collect(ap.rpkiStatus) AS rpkiStatuses,
head(collect(a)) AS primaryAsn,
head(collect(ap)) AS primaryPrefix
OPTIONAL MATCH (primaryPrefix)-[:CONFLICTS_WITH]->(conflict:ASN)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn,
collect(conflict.name) AS conflictAsns
OPTIONAL MATCH (h)-[:HAS_REGISTRAR]->(reg:REGISTRAR)
OPTIONAL MATCH (h)-[:REGISTERED_BY]->(org:ORGANIZATION)
OPTIONAL MATCH (h)-[:CHILD_OF]->(tld:TLD)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
collect(reg.name) AS registrars,
collect(org.name) AS organizations,
collect(tld.name) AS tlds
OPTIONAL MATCH (h)-[:HAS_EMAIL]->(em:EMAIL)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds,
collect(em.name) AS emails
OPTIONAL MATCH (h)-[:HAS_PHONE]->(ph:PHONE)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails,
count(ph) AS phoneCount
OPTIONAL MATCH (h)<-[:MAIL_FOR]-(mx:HOSTNAME)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount,
collect(mx.name)[0..20] AS mxHosts
OPTIONAL MATCH (h)<-[:NAMESERVER_FOR]-(ns:HOSTNAME)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts,
collect(ns.name) AS nameservers
OPTIONAL MATCH (h)-[spf:SPF_A|SPF_EXISTS|SPF_INCLUDE|SPF_IP|SPF_MX|SPF_REDIRECT]->(spfTarget)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers,
collect({mechanism: type(spf), target: spfTarget.name})[0..50] AS spf
OPTIONAL MATCH (h)-[:SIGNED_WITH]->(alg:DNSSEC_ALGORITHM)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf,
collect(alg.name) AS dnssecAlgorithms
OPTIONAL MATCH (h)-[:DMARC_REPORTS_TO]->(dm:DMARC_RECIPIENT)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf, dnssecAlgorithms,
collect(dm.name)[0..5] AS dmarcRecipients
OPTIONAL MATCH (h)-[:DKIM_SIGNED_BY]->(dk:VENDOR)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf, dnssecAlgorithms,
dmarcRecipients,
collect(coalesce(dk.displayName, dk.name))[0..5] AS dkimVendors
OPTIONAL MATCH (h)-[:HAS_SIGNAL]->(hs:THREAT_SIGNAL_TYPE)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf, dnssecAlgorithms,
dmarcRecipients, dkimVendors,
collect(hs.name) AS dnsSignals
CALL { WITH primaryAsn MATCH (primaryAsn)-[:BGP_NEIGHBOR]-(peer:ASN) RETURN count(peer) AS asnPeerCount }
RETURN h.name AS name,
h.rank AS rank,
h.verdictLevel AS verdictLevel,
h.verdictScore AS verdictScore,
h.verdictBlocking AS verdictBlocking,
h.verdictCoverage AS verdictCoverage,
h.verdictAdvisory AS verdictAdvisory,
h.threatSources AS threatSources,
h.threatFirstSeen AS threatFirstSeen,
h.threatLastSeen AS threatLastSeen,
h.isTor AS isTor,
h.isVpn AS isVpn,
h.isProxy AS isProxy,
h.isC2 AS isC2,
h.isPhishing AS isPhishing,
resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf,
dnssecAlgorithms, dmarcRecipients, dkimVendors, dnsSignals,
h.companyName AS companyName,
h.companyIndustry AS companyIndustry,
h.companyHqCountry AS companyHqCountry,
h.companyHqCity AS companyHqCity,
asnPeerCountRun yourself →The observed subdomain count, to depth 3.
MATCH (h:HOSTNAME {name: $host})
CALL { WITH h MATCH (h)<-[:CHILD_OF*1..3]-(sub:HOSTNAME) RETURN count(sub) AS subdomainCount }
RETURN subdomainCountRun yourself →Technologies the company behind this domain has been observed running, most widely adopted first.
MATCH (:HOSTNAME {name: $host})-[:RUNS_TECHNOLOGY]->(t:TECHNOLOGY)
WITH t.name AS name, t.category AS category, t.adopterCount AS adopters
ORDER BY adopters DESC, name
WITH collect({name: name, category: category}) AS technologies, count(*) AS total
RETURN total, technologies[0..20] AS technologiesRun yourself →Peer companies (outbound SIMILAR_TO).
MATCH (:HOSTNAME {name: $host})-[:SIMILAR_TO]->(peer:HOSTNAME) RETURN peer.name AS host ORDER BY host LIMIT 8Run yourself →The parent company's domain and this company's domain portfolio (PARENT_OF).
MATCH (h:HOSTNAME {name: $host})
OPTIONAL MATCH (h)<-[:PARENT_OF]-(parent:HOSTNAME)
WITH h, collect({host: parent.name, company: parent.companyName})[0..3] AS parents
OPTIONAL MATCH (h)-[:PARENT_OF]->(child:HOSTNAME)
RETURN parents, collect({host: child.name, company: child.companyName})[0..10] AS portfolioRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.