Analysis of wishbonedogs.xyz, created on 27 July 2026 and currently active, shows infrastructure consistent with a phishing operation. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and uses Cloudflare nameservers damiete.ns.cloudflare.com and malavika.ns.cloudflare.com, resolving to the IP address 172.67.217.69, a Cloudflare‑owned address that masks the underlying hosting provider. The domain appears on a single security blocklist and has been actively blocked by PhishDestroy, indicating that at least one reputable anti‑phishing feed has identified malicious activity associated with it.
VirusTotal records show that the domain was scanned by 91 AV engines, none of which reported a detection at the time of analysis; this lack of detection does not constitute a safety guarantee, as phishing payloads often evade static scanners. No public Safe Browsing, OTX, SSL certificate, HTTP status, or page‑title information is presently available, leaving the content layer unverified. Consequently, the primary confidence stems from the registrar information, blocklist inclusion, and the PhishDestroy block.
Defenders should add wishbonedogs.xyz to outbound and inbound filtering rules, monitor DNS queries for the Cloudflare IP range, and enforce URL reputation checks that incorporate the blocklist entry. Continuous re‑scanning with dynamic analysis tools is recommended to detect any future payload changes, and any observed credential submissions to the domain should be treated as compromised. Organizations should also consider sharing any new indicators of compromise with relevant threat‑sharing communities to improve collective detection.