Analysis of the domain holiganbet-siteleradres2026.cfd indicates an active phishing infrastructure as of the report date, July 31, 2026. The domain was registered on July 27, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is delegated to the Cloudflare name servers jermaine.ns.cloudflare.com and princess.ns.cloudflare.com. DNS resolution points to the IP address 188.114.96.3, a host that is currently listed on at least one external security blocklist. The domain has been flagged by the PhishDestroy blocklist, confirming its inclusion in known malicious collections.
A VirusTotal scan was performed by 91 AV vendors; while no vendor flagged the domain at the time of scanning, the absence of detections does not constitute evidence of benign intent and should not be interpreted as a safety guarantee. The domain appears on a single security blocklist, underscoring that threat intelligence sources have begun to surface its malicious use. No additional information regarding SSL certificates, HTTP response codes, page titles, or brand targeting has been disclosed, leaving those vectors unverified.
Consequently, defenders should continue to treat holiganbet-siteleradres2026.cfd as a high‑confidence phishing indicator. Recommended mitigation steps include adding the domain to network‑level deny lists, updating endpoint protection signatures, and monitoring for any outbound connections to the associated IP address. Ongoing observation is advised to capture any future changes in hosting, content, or detection status.