Analysis of bop.free-drop.fun shows a newly registered domain created on July 28, 2026 and currently active. The authoritative name servers are brynne.ns.cloudflare.com and rudy.ns.cloudflare.com, indicating the use of Cloudflare DNS services. Registration was performed through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar that has been associated with short‑lived malicious domains in prior investigations.
DNS resolution points to the address 188.114.97.3, an IP frequently observed in other phishing infrastructure and hosted by a provider that offers shared hosting services. The domain appears on a single security blocklist, PhishDestroy, which has already flagged it as malicious, confirming that at least one external source considers the domain hostile. VirusTotal reports that the domain was scanned by 91 vendors without any current detections; however, the absence of a detection does not constitute evidence of safety, especially given the recent creation date and blocklist entry.
No publicly available SSL certificate details, HTTP response codes, or page title information have been disclosed, leaving the content and transport security of the site unverified. Consequently, while the exact phishing payload or targeted brand remains unknown, the combination of a fresh registration, Cloudflare name servers, a known malicious IP, and inclusion on PhishDestroy suggests a high likelihood of phishing activity. Defenders should block bop.free-drop.fun at network perimeters, include the IP 188.114.97.3 in threat‑intel feeds, monitor DNS queries for this domain, and continue to review any emerging telemetry that may reveal the hosted content or associated credential‑harvesting mechanisms.