Analysis of perabetmobilgirisi.icu shows a newly created domain (creation date July 28 2026) that resolves to the Cloudflare‑managed address 104.21.35.195. The domain is delegated to indie.ns.cloudflare.com and matt.ns.cloudflare.com, indicating use of Cloudflare’s DNS and proxy services, a pattern frequently observed in phishing infrastructure because it offers rapid deployment and obscures the underlying hosting environment. Registration was performed through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar that has hosted other malicious sites in recent investigations.
The domain is currently listed on a single security blocklist and has been actively blocked by the PhishDestroy service, confirming that at least one anti‑phishing feed has identified it as malicious. VirusTotal records indicate that the domain was scanned by 91 antivirus and URL‑reputation vendors; none reported a detection, but the absence of a flag does not constitute evidence of safety, especially given the domain’s recent creation and its appearance on a blocklist. No public SSL certificate details, HTTP status codes, page title, or content analysis are available, so the specific landing page content remains unknown.
The combination of a fresh registration, Cloudflare front‑end, and inclusion on an anti‑phishing blocklist suggests a high likelihood of phishing intent. Defenders should proactively block perabetmobilgirisi.icu at perimeter firewalls, DNS filtering layers, and endpoint protection solutions, and continue to monitor the IP 104.21.35.195 for any associated malicious activity. Ongoing telemetry collection is advised to capture any future payloads or redirects that may be introduced as the campaign evolves.