The domain mzrtkb.cfd was registered on July 26 2026 via Aceville Pte. Ltd. It is hosted on Cloudflare infrastructure, as indicated by the authoritative nameservers elijah.ns.cloudflare.com and elisabeth.ns.cloudflare.com and resolves to the IP address 188.114.96.3. VirusTotal analysis shows that six of ninety‑one scanning engines have flagged the domain, demonstrating a moderate detection rate. The domain is currently listed on one public security blocklist and has been actively blocked by the PhishDestroy service.
Its status is reported as active, meaning the domain continues to resolve and may be serving malicious content. No additional public intelligence such as Safe Browsing verdicts, Open Threat Exchange reports, or SSL certificate details are presently available, leaving the exact nature of the hosted payload unknown. The combination of recent registration, Cloudflare name servers, a non‑reputable registrar, and multiple vendor detections suggests a high likelihood of phishing use, consistent with the generic phishing classification.
Defenders should add mzrtkb.cfd to outbound and inbound deny lists, monitor DNS queries for the 188.114.96.3 address, and enforce URL filtering solutions that incorporate the existing blocklist entry. Because the domain is still active, continuous re‑evaluation is recommended; any new detection from additional scanning services or observed malicious traffic should trigger an immediate escalation. Organizations employing email security gateways should ensure that messages containing links to this domain are quarantined or rejected, and incident response teams should be prepared to investigate any user reports of credential‑harvesting attempts linked to mzrtkb.cfd.