bop.meme-pass.io was registered on July 10 2026 through Web Commerce Communications Limited dba WebNic.cc. The domain resolves to the IP address 104.21.4.98 and is served by Cloudflare, as indicated by the authoritative nameservers ashley.ns.cloudflare.com and jasper.ns.cloudflare.com. The domain is currently listed on a single security blocklist and has been actively blocked by the PhishDestroy mitigation service, confirming that at least one upstream provider has identified it as malicious. The threat classification assigned by internal intelligence is generic phishing, and the incident remains under investigation with an active status.
Infrastructure analysis shows the hosting IP belongs to Cloudflare’s edge network, a common choice for fast‑flux or abuse‑hiding operations. No additional hosting details, such as autonomous system number or geographic location, are disclosed in the available data. The registrar information does not reveal any privacy protection, allowing the registration entity to be observed directly. Publicly visible attributes such as the website’s page title, SSL certificate details, HTTP response codes, or any brand targeting cues have not been captured at this time, leaving the exact content of the site unknown.
Consequently, the precise phishing lure cannot be confirmed without further probing. Defenders should add bop.meme-pass.io to local deny lists, enforce DNS‑based block policies, and monitor outbound connections to the associated Cloudflare edge IP. Because the domain is actively used, continuous re‑evaluation of blocklist status and any emerging detection from additional vendors is recommended. Organizations employing email or web filtering should ensure the domain is included in phishing‑specific rule sets to reduce user exposure while investigations continue.