Analysis of ponsfamily.cc shows a newly registered domain created on July 29, 2026 that is actively serving a generic phishing campaign. The domain resolves to the IP address 188.114.96.3 and is hosted on nameservers dimitris.ns.cloudflare.com and jule.ns.cloudflare.com, indicating the use of Cloudflare’s DNS infrastructure. Registration was completed through Global Domain Group LLC, a registrar that does not provide additional protective metadata.
Independent threat intelligence feeds have placed the domain on three security blocklists, specifically PhishDestroy, MetaMask, and SEAL, confirming that multiple defensive platforms have already identified it as malicious. VirusTotal scans report that two of ninety‑one security vendors flagged the domain, providing early corroboration of its malicious intent. The domain remains active as of the report date, July 30, 2026, and no evidence of mitigation or takedown has been observed.
No page title or content analysis is presently available, so the exact phishing lure or targeted brand cannot be confirmed. Defenders should immediately block traffic to 188.114.96.3 and to ponsfamily.cc at the network perimeter, update URL filtering lists with the identified blocklist entries, and monitor for any related C2 patterns that may emerge from the same IP or nameserver set. Continuous re‑scanning of the domain on multi‑vendor platforms is recommended to capture any new detections as the campaign evolves.