# PhishDestroy threat dossier — g103u.xyz ================================================================ Fetched: 2026-07-26 19:22:30 UTC Canonical: https://phishdestroy.io/domain/g103u.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 9/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, CyRadar, Emsisoft, Forcepoint ThreatSeeker, Fortinet, LevelBlue, Netcraft, Webroot AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Gname.com Pte. Ltd. Nameservers: ["ns1.1111343.com", "ns2.1111343.com", "ns3.1111343.com", "ns4.1111343.com"] HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 07:53:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-26 20:20:20 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 07:54:16 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] g103u.xyz Generic Phishing Infrastructure Detected The domain g103u.xyz has been identified as an active high-risk generic phishing site as of July 26, 2026. This domain remains online, responding with HTTP status 200. Registration records show that g103u.xyz is registered through Gname.com Pte. Ltd. and is utilizing a set of nameservers hosted under the 1111343.com domain: ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, and ns4.1111343.com. At present, there is no public evidence attributing this domain to any specific brand or organization; the precise nature of the phishing content or its intended target remains unconfirmed due to lack of direct site analysis or page title data. Technical analysis reveals that g103u.xyz is already blocked by PhishDestroy and is listed on one security blocklist. VirusTotal reports that 9 out of 91 security vendors currently identify this domain as malicious, which further supports its classification as a phishing threat. This detection rate indicates a moderate level of consensus within the security community, suggesting that defenders should treat the domain as hostile. The domain's continued operation and limited blocklist presence may facilitate ongoing phishing campaigns. Security teams are advised to implement immediate blocking of g103u.xyz within their environments and monitor for any network traffic related to this domain. Further investigation into associated infrastructure, such as the referenced nameservers, may reveal additional related threats. As there is no information regarding the hosting IP, SSL certificate, or visual content, organizations should rely on reputation-based indicators and threat intelligence sources. The lack of clarity around the specific phishing content emphasizes the need for ongoing monitoring and rapid response should further details emerge. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/g103u.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=g103u.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 199,310 domains (68,635 alive under monitoring, 129,126 confirmed takedowns/dead). Site: https://phishdestroy.io