Analysis of trust-monitor.org indicates that the domain was registered on June 18, 2026 through Cloudflare, Inc. and is currently resolved to the IPv4 address 185.214.74.197, using the Cloudflare nameservers damien.ns.cloudflare.com and pearl.ns.cloudflare.com. The domain appears on two independent security blocklists, PhishDestroy and ScamSniffer, and its status remains active despite the listings. VirusTotal has recorded scans from 91 antivirus and URL‑reputation vendors; none of the scanned samples returned a detection, a result that does not constitute confirmation of benign intent.
The absence of detections, combined with the recent registration date and the presence on established blocklists, suggests that the domain is being used for malicious purposes, most likely a credential‑harvesting operation. At present, no public page title, brand target, or specific phishing kit information is available, leaving the exact impersonated service undefined. Defenders should continue to block the domain at network perimeter devices, update URL filtering policies to include the listed blocklists, and monitor DNS queries for the IP address 185.214.74.197 for any anomalous activity.
Additional investigation, such as sandboxed page retrieval and content analysis, is recommended to determine the precise payload and any associated command‑and‑control infrastructure. Until further evidence is gathered, the domain should be treated as a high‑risk indicator and excluded from trusted traffic flows.