The domain 3658fry58213.cc was registered on 19 June 2026 through DYNADOT LLC and is currently active. DNS resolution points to the IPv4 address 40.81.18.27 and the authoritative name servers are n1.xundns.com and n2.xundns.com. VirusTotal analysis shows that 16 out of 91 scanning engines have flagged the domain as malicious, indicating a consensus among a subset of commercial detection products.
The domain is also listed on a public phishing blocklist operated by PhishDestroy and appears on one additional security blocklist, reinforcing its classification as a phishing‑related resource. No public evidence of SSL certificates, HTTP response codes, page titles, or content snapshots is available in the current intelligence set, so the exact landing page characteristics remain unknown. The lack of visible branding or targeted brand information further limits attribution, but the aggregate signals from vendor detections and blocklist listings justify a high‑risk rating.
Defenders should immediately incorporate 3658fry58213.cc into DNS‑based deny lists, update firewall and proxy rule sets to deny traffic to the resolved IP 40.81.18.27, and monitor for any outbound connections that may attempt to resolve the domain. Continuous ingestion of updated feed data from VirusTotal, PhishDestroy, and other reputable blocklist providers is recommended to capture any changes in detection status. Until a detailed content analysis is performed, the domain should be treated as a confirmed phishing vector and blocked at the network perimeter.