The domain joinclub-verify.com was registered on June 18, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and remains active as of the report date, July 30, 2026. DNS resolution points to the IP address 188.114.97.3, and the authoritative name servers are brady.ns.cloudflare.com and venus.ns.cloudflare.com, indicating Cloudflare’s DNS service is being used for the infrastructure. VirusTotal has recorded six detections out of ninety‑one scanning engines, confirming that multiple security vendors have identified malicious activity associated with the host.
The domain is currently listed on one external security blocklist and is explicitly blocked by the PhishDestroy mitigation service, reinforcing the consensus that it is being used for credential‑phishing campaigns. No additional public intelligence such as Safe Browsing status, Open Threat Exchange entries, or SSL/TLS certificate details is available. The limited visibility leaves uncertainty around the exact phishing payload, targeted brands, or the hosting environment beyond the Cloudflare name server indication.
Defenders should prioritize adding joinclub-verify.com to inbound and outbound filtering rules, enforce DNS‑level blocking, and monitor traffic to the resolved IP 188.114.97.3 for anomalous authentication attempts. Continuous re‑scanning with multi‑engine services is advised to capture any evolution in detection coverage, and any observed exploitation attempts should be reported to relevant threat‑sharing communities to augment collective defenses.