The domain tuccobetgrs.info was registered on July 27, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is served by Cloudflare DNS (gigi.ns.cloudflare.com, major.ns.cloudflare.com). DNS resolution points to IP address 188.114.97.3, an address owned by Cloudflare’s global network, a hosting environment frequently leveraged for rapid‑deployment phishing infrastructure. The domain appears on a single security blocklist and is actively blocked by PhishDestroy, indicating that at least one threat‑intelligence feed has cataloged it as malicious. VirusTotal has processed the domain with 91 scanning engines; none reported a detection, but this lack of a flag does not constitute evidence of safety and should be interpreted as inconclusive.
No SSL certificate metadata, HTTP status codes, page title, or content snapshots have been published, leaving the exact page content and any impersonated brand unverified. The absence of a disclosed brand target suggests the operation may employ a generic credential‑harvesting lure rather than a focused brand spoof, but this remains uncertain without direct page analysis. Defenders should add tuccobetgrs.info to local deny lists, monitor DNS queries for the associated Cloudflare IP, and consider outbound filtering for unexpected Cloudflare‑hosted destinations.
Continuous re‑scanning with VirusTotal and other sandbox services is advised to detect any future payloads. User education campaigns should emphasize scrutiny of unsolicited communications that reference newly created domains, encouraging verification of URLs before entering credentials. The domain remains active, and ongoing observation is recommended.