Analysis indicates that the domain 65.jj38390.vip is presently active and associated with a phishing campaign. The domain resolves to the IPv4 address 104.208.98.216, confirming that traffic is directed to a single host. Infrastructure monitoring shows that the domain has been added to at least one external security blocklist and was explicitly blocked by the PhishDestroy filtering service, reinforcing the assessment of malicious intent. VirusTotal scanning recorded detections from six out of ninety‑one antivirus and URL‑reputation engines, providing independent confirmation that the domain exhibits characteristics commonly observed in phishing infrastructure.
Nameserver information could not be retrieved, which may reflect the use of dynamic or obscured DNS configurations intended to hinder attribution. No SSL certificate details, HTTP status codes, or page title information are available in the current intelligence set, and the registrar metadata is absent, limiting the ability to trace ownership or hosting provider. The limited visibility into the web content means the exact phishing lure or target brand cannot be identified at this stage.
Given the confirmed detections, blocklist presence, and active status, defenders should treat the domain as high‑risk: network firewalls and DNS resolvers ought to deny queries to 65.jj38390.vip, the associated IP 104.208.98.216 should be added to deny lists, and security appliances should continue to monitor for any outbound connections to that address. Continuous re‑evaluation is advised, including periodic rescans, sandbox execution of any retrieved payloads, and correlation with threat‑intel feeds to capture potential evolution of the campaign. Until further evidence emerges, the precautionary stance remains to block and monitor all activity linked to this domain.