Analysis of the domain bullpen.help shows that it is actively used for generic phishing as of the report date, July 31, 2026. The domain was registered through NameSilo, LLC on July 07, 2026 and is served by Cloudflare nameservers darwin.ns.cloudflare.com and kiki.ns.cloudflare.com. DNS resolution points to the IP address 172.67.136.189, which is a Cloudflare‑hosted address.
The site has been added to at least one public security blocklist and is currently blocked by the PhishDestroy service, indicating that threat‑intel feeds have identified it as malicious. VirusTotal has recorded scans from 91 antivirus and URL‑reputation vendors; none of those vendors have generated a detection at the time of analysis, but the absence of detections does not equate to a clean verdict and should not be taken as evidence of safety. No additional public telemetry such as Google Safe Browsing, OTX, SSL certificate details, HTTP response codes, trust‑score metrics, or page‑title information is available in the supplied intelligence.
Consequently, the exact content served by the site, its phishing kit, or targeted brand remain unknown. Defenders should treat the domain as hostile infrastructure: block network traffic to 172.67.136.189 and to the hostname bullpen.help at perimeter devices, update URL filtering and DNS sinkhole rules, and monitor for any newly observed indicators that may emerge from future scans or community reports. Continuous re‑evaluation is advised, as the lack of current vendor detections and limited telemetry could change if the operators modify the payload or hosting configuration.