The domain bitwinex.io was registered on June 19 2026 through GoDaddy.com, LLC. Its authoritative name servers are jo.ns.cloudflare.com and rudy.ns.cloudflare.com, indicating the use of Cloudflare's DNS service. DNS resolution returns the address 104.26.10.14, an IP that belongs to Cloudflare's network and is commonly leveraged for proxy‑based phishing infrastructure. The domain appears on a single security blocklist and is actively listed by PhishDestroy, confirming that at least one reputable anti‑phishing feed has identified it as malicious.
VirusTotal scans show that 1 of 91 security vendors flagged the domain, demonstrating that automated detection has produced a positive result despite the low overall detection ratio. No additional public reputation services, Safe Browsing status, or OTX indicators were provided in the current intelligence set. The short age of the domain—created less than two months before the report date—combined with its Cloudflare front‑end and the single vendor flag suggest a fast‑deployment campaign aimed at exploiting the brief window before broader community awareness.
Defenders should add bitwinex.io to blocklists at the DNS or proxy layer, monitor outbound connections to the associated Cloudflare IP, and consider sharing the indicator with threat‑intel platforms to improve collective detection. Continuous re‑scanning on VirusTotal and similar services is recommended, as additional vendor detections may appear as the campaign matures.