On July 30, 2026, the domain 10120bets10.com was observed to be actively used for generic phishing. The domain was registered only five days earlier, on July 25, 2026, through the registrar Fewmoretaps OU d/b/a Trustname.com. It is hosted on Cloudflare infrastructure, as indicated by the authoritative nameservers armando.ns.cloudflare.com and gloria.ns.cloudflare.com, and resolves to the IP address 188.114.96.3. The short registration window and immediate appearance in malicious infrastructure suggest a purpose‑built operation rather than a compromised legitimate site.
Threat‑intelligence feeds have recorded the domain on a single security blocklist, and the anti‑phishing service PhishDestroy has already blocked it, yet the domain remains reachable, confirming its active status. VirusTotal analysis shows that one out of ninety‑one scanned security vendors raised a detection on the domain, providing independent corroboration of malicious intent. No additional public reputation scores, SSL certificate details, or HTTP response codes are currently available, limiting the depth of technical profiling. Given the limited but consistent indicators—recent registration, Cloudflare hosting, blocklist entry, PhishDestroy block, and a VirusTotal vendor flag—defenders should treat the domain as high‑risk.
Network perimeter tools should deny outbound connections to 188.114.96.3, and DNS filtering solutions should add 10120bets10.com to deny lists. Continuous monitoring of the IP address and associated Cloudflare nameservers is advised, as the infrastructure may be reused for subsequent fraudulent campaigns. Organizations relying on email or web gateway security should ensure that their policies reference the latest blocklist feeds that include this domain. Further investigation, such as retrieving the website’s HTML title or checking for SSL certificate fingerprints, would improve confidence in attribution, but the current evidence already warrants immediate mitigation.