# mahjongwin138f.vip — SUSPICIOUS > mahjongwin138f.vip was used for phishing activities. Users should avoid interaction and ensure their credentials remain secure. ## Summary PhishDestroy identifies mahjongwin138f.vip as a domain involved in generic phishing activities, posing a medium risk to users. The domain was likely used to deceive victims into revealing sensitive information such as login credentials or personal data through fraudulent means. The threat aims to exploit unsuspecting users by mimicking legitimate services or offers. The domain mahjongwin138f.vip was registered through Dynadot Inc and resolves to the IP address 188.114.96.3. It was created on February 28, 2026, which indicates it is a recent registration, aligning with typical tactics where attackers deploy fresh domains to evade detection. The infrastructure details suggest a possible attempt to quickly establish malicious campaigns before takedown. Currently, the mahjongwin138f.vip domain is offline, reducing immediate risk to users. However, given the nature of phishing threats, users are advised to remain vigilant against similar domains and avoid clicking on unsolicited links or providing credentials on suspicious websites. Organizations should continue monitoring related domains and IPs to prevent future attacks and maintain updated email and web filtering rules. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: MAHJONGWIN138 - Situs Mahjong Slot Gampang Menang Hari Ini ## Domain Intelligence - Registered: 2026-03-04 15:07:01 - Registrar: Dynadot LLC - Country: US - IP: 188.114.96.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["miles.ns.cloudflare.com", "beth.ns.cloudflare.com"] - SSL Issuer: Let's Encrypt / E8 ## Detection Status - VirusTotal: 2 vendors flagged Vendors: ["Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://i.ibb.co/svjkDnbT/7c17cc2d82a0.png - Cloudflare Radar: https://radar.cloudflare.com/scan/fe8a9d8e-f4a3-4b6c-9394-a120e1fe5f95 - Wayback Machine: https://web.archive.org/web/https://mahjongwin138f.vip - PhishDestroy: https://phishdestroy.io/domain/mahjongwin138f.vip/ - LLM endpoint: https://phishdestroy.io/domain/mahjongwin138f.vip/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/mahjongwin138f.vip/ Last updated: 2026-03-19