Analysis indicates that the domain amshel.sbs was registered on April 24, 2026 through Dynadot Inc and remains active as of the report date. The authoritative name servers are alan.ns.cloudflare.com and princess.ns.cloudflare.com, pointing to a Cloudflare‑managed hosting environment. DNS resolution returns the single IPv4 address 188.114.96.3, which is associated with a public Cloudflare edge node rather than a dedicated backend server, a pattern frequently observed in fast‑flux or proxy‑based phishing infrastructure.
The domain is listed on one known security blocklist and has been explicitly blocked by the PhishDestroy sinkhole, confirming that at least one defensive feed has observed malicious activity originating from this host. VirusTotal scans report that two out of ninety‑one antivirus engines flag the domain, providing additional, albeit limited, corroboration of its risk profile. No public SSL certificate details, HTTP response codes, page title, or Safe Browsing verdict are presently available, leaving the web content and transport security characteristics uncertain.
The limited detection footprint suggests that the campaign may be in an early deployment stage or that the operators are employing evasive hosting techniques to stay below radar thresholds. Defenders should proactively deny any network traffic to 188.114.96.3, incorporate amshel.sbs into URL filtering and email gateway rules, and monitor for related Cloudflare resolver entries. Given the active registration, Cloudflare name servers, and existing blocklist presence, the domain should be treated as high‑risk and blocked until a thorough forensic capture of the hosted page can be performed.