# p42o.xyz — MALICIOUS > Analyze p42o.xyz for phishing risks. Active domain flagged for suspicious activity linked to 'welcome-BET365'. Stay informed and protected. ## Summary PhishDestroy identifies p42o.xyz as a high-risk generic phishing domain. The page title 'welcome-BET365' suggests it targets users with fake betting-related content, aiming to deceive and steal credentials. This domain, registered on April 3, 2025, resolves to IP 45.196.247.191 and is registered via Gname.com Pte. Ltd. It appears on one security blocklist and has been reported in two AlienVault OTX threat pulses. VirusTotal flags it by 15 out of 95 security vendors, confirming its malicious nature. Currently active, p42o.xyz remains a threat. PhishDestroy recommends immediate caution and blocking to prevent user exposure to credential theft or fraud associated with this domain. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Page title: welcome-BET365 ## Domain Intelligence - Registered: 2025-04-03 11:07:40 - Registrar: Gname.com Pte. Ltd. - Country: SG - IP: 45.196.247.191 - Nameservers: ["A.SHARE-DNS.COM", "B.SHARE-DNS.NET"] - SSL Issuer: R13 ## Detection Status - VirusTotal: 15 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "BitDefender", "CyRadar", "ESET", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Gridinsoft", "Kaspersky", "Lionic", "SOCRadar", "Sophos", "VIPRE", "Webroot"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019ba863-8315-740d-aa9d-eb3a1850eee9.png - PhishDestroy: https://phishdestroy.io/domain/p42o.xyz/ - LLM endpoint: https://phishdestroy.io/domain/p42o.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/p42o.xyz/ Last updated: 2026-03-19