# g87g.xyz — MALICIOUS > g87g.xyz is a high-risk phishing domain targeting users with fake BET365 pages. Avoid interaction; domain is currently offline after detection. ## Summary PhishDestroy identifies g87g.xyz as a high-risk phishing domain primarily used for generic phishing attacks. The domain impersonates legitimate betting services, as evidenced by the page title "welcome-BET365," aiming to deceive users into divulging sensitive information. Supporting intelligence reveals that 13 out of 95 VirusTotal scanners flagged this domain, indicating notable suspicion among security vendors. The domain was created recently on March 9, 2026, and was registered through Gname.com Pte. Ltd. It resolves to the IP address 103.233.249.125 and is listed on at least one security blocklist, reinforcing its malicious nature. Currently, g87g.xyz has been taken offline, mitigating further risk to potential victims. Users are advised to avoid engaging with this domain or any related communications. Continuous monitoring and blocking of domains linked to phishing campaigns like this remain critical for cybersecurity hygiene. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 0) - Page title: welcome-BET365 ## Domain Intelligence - Registered: 2026-03-09 01:07:01 - Registrar: Gname.com Pte. Ltd. - Country: SG - IP: 103.233.249.125 - IP Country: HK - IP City: Kwai Chung - IP Org: AS132839 POWER LINE DATACENTER - Nameservers: ["ns1.1111343.com", "ns2.1111343.com", "ns3.1111343.com", "ns4.1111343.com"] - SSL Issuer: none ## Detection Status - VirusTotal: 13 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "CRDF", "CyRadar", "Emsisoft", "Fortinet", "Kaspersky", "Lionic", "Netcraft", "SOCRadar", "Sophos", "Trustwave", "Webroot"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019ccffc-581b-73b7-a0a4-d331d6cce024.png - Cloudflare Radar: https://radar.cloudflare.com/scan/5ffd2a48-5660-44c7-917e-e3389fd12326 - Wayback Machine: https://web.archive.org/web/https://g87g.xyz - PhishDestroy: https://phishdestroy.io/domain/g87g.xyz/ - LLM endpoint: https://phishdestroy.io/domain/g87g.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/g87g.xyz/ Last updated: 2026-03-19