The domain ecoinda.org was registered on May 23, 2026 through the registrar Gname.com Pte. Ltd. and is currently delegated to the Cloudflare nameservers gigi.ns.cloudflare.com and matt.ns.cloudflare.com. DNS resolution points to the address 104.21.67.133, an IP owned by Cloudflare’s network, which is commonly leveraged by threat actors for fast‑flux or anonymised hosting. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, indicating that at least one reputable anti‑phishing community has identified it as malicious.
VirusTotal analysis shows that one of ninety‑one scanned vendors flagged the domain, providing an additional independent detection signal. No public page title, SSL certificate details, or HTTP response codes are available in the current intelligence set, leaving the content of the site uncharacterised beyond the generic phishing classification. The limited detection surface—one blocklist entry and a single vendor flag—suggests that the campaign may be in an early deployment phase, but the presence of Cloudflare hosting and a recent registration date align with typical infrastructure patterns used in phishing operations.
Defenders should add ecoinda.org to network‑level deny lists, enforce DNS‑based blocking, and monitor for any outbound connections to the associated IP address. Continuous re‑scanning of the domain on multi‑engine platforms is advised to capture any escalation in detection counts, and any future observations of page content or credential‑harvesting endpoints should be incorporated into threat intelligence feeds to improve attribution and response efficacy.