u92a[.]xyz
“welcome-BET365”
The domain u92a.xyz presents a fraudulent gambling platform, as indicated by its page title "welcome-BET365" and its impersonation of the Bet365 brand. This site poses a threat by deceiving users into engaging with an unauthorized betting service, potentially leading to financial loss and data theft.
Technical analysis reveals 23 out of 95 VirusTotal vendors flagged the domain as malicious, with detections from ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, and Cluster25. The domain is registered via Gname.com Pte. Ltd., hosted on IP 45.196.247.179 (Hong Kong, AS140224 Nebula Global LLC), created on 2026-02-17, and lacks SSL encryption. It uses nameservers A.SHARE-DNS.COM and B.SHARE-DNS.NET.
The site is currently offline, reducing immediate risk, but its recent creation and high detection rate indicate a significant threat if reactivated. The absence of SSL and impersonation of a legitimate brand elevate the risk level for potential visitors.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | u92a.xyz |
phishing | Phishing Block |
| DigiCert UltraDNS | u92a.xyz |
malicious | Sinkholed |
| DNS4EU | img.esportsdata.cc |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
VirusTotal Analysis
Evidence & External Reports
PD-20260221-575692 Recipient: complaint@gname.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive