The domain gcg2.live was registered on July 28, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolved to the IP address 188.114.97.3. Its authoritative nameservers are brady.ns.cloudflare.com and cheryl.ns.cloudflare.com, indicating that the domain is hosted on Cloudflare’s network. The domain is listed as active and has been classified as a generic phishing threat, with a risk level marked as under investigation. VirusTotal records show that the domain was scanned by 91 antivirus and URL‑reputation vendors; none of the scanned engines reported a detection at the time of analysis.
While the absence of detections does not constitute evidence of benign intent, it confirms that the domain has not yet triggered a signature or heuristic flag in the examined sample set. The domain appears on a single security blocklist and is explicitly blocked by PhishDestroy, demonstrating that at least one external anti‑phishing service has identified it as malicious. No additional public reputation services, Safe Browsing checks, or Open Threat Exchange entries are referenced in the available intelligence.
Consequently, the observable infrastructure suggests deliberate use of Cloudflare’s DNS to obscure the originating host, a pattern commonly observed in phishing campaigns seeking rapid deployment and easy takedown resistance. Defenders should consider adding gcg2.live to network and endpoint block lists, monitor DNS queries for the associated Cloudflare nameservers, and continue to track any future detections from additional scanning engines. Ongoing observation is advised to determine whether the domain begins to host payloads, serve malicious redirects, or engage in credential harvesting, as the current evidence set does not reveal the exact content or payload delivered by the site.