62420[.]xyz
“welcome-BET365”
This domain, 62420.xyz, was registered on 14 Feb 2026 through Gname.com Pte. Ltd. and is currently active. The authoritative nameservers are a.share-dns.com, a1.share-dns.com, b.share-dns.net, and b1.share-dns.net, indicating use of a shared DNS service. DNS resolution points to the single IPv4 address 103.27.177.164, which is the only observed hosting endpoint. The domain is classified as a generic phishing site and assigned a high risk level. VirusTotal analysis shows that 12 of 91 scanned security vendors flagged the domain as malicious, providing independent confirmation of suspicious activity. No additional infrastructure such as extra IPs or CDN layers has been identified. The short lifespan since registration and reliance on shared DNS suggest a rapid‑deployment infrastructure typical of opportunistic phishing campaigns. Uncertainty remains regarding the specific payload or credential‑harvesting mechanisms employed, as no page content has been publicly analysed. Defenders should add 62420.xyz to blocklists, enforce DNS sink‑holing for the resolved IP, and monitor for any related sub‑domains or similar name‑server patterns. Continuous re‑scanning on VirusTotal or equivalent platforms is recommended to capture any changes in detection status.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | 17657.xyz |
malicious | Sinkholed |
| DNS4EU | ssl.hw301.xyz |
malicious | Sinkholed |
| DigiCert UltraDNS | 62420.xyz |
malicious | Sinkholed |
| Cloudflare DNS | 62420.xyz |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | 62420.xyz |
malicious | Sinkholed |
| OpenDNS | 62420.xyz |
phishing | Phishing Block |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
PD-20260714-218D33 Recipient: complaint@gname.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive