distribution-qubic[.]app
Evidence Summary
Distribution-qubic.app was registered on 21 February 2026 and presently resolves to 188.114.97.3, an address owned by AS13335 Cloudflare, Inc. in the United States. The site presented the HTTP title “Just a moment…”, a generic placeholder often used by Cloudflare challenge pages. The domain appears on two independent phishing blocklists, PhishDestroy and ScamSniffer, and received a Gridinsoft trust score of 0 out of 100, indicating a high confidence of malicious intent. VirusTotal analysis shows that one of ninety‑five scanning engines flagged the domain, corroborating the blocklist findings.
The SSL certificate presented for the host is identified as “WE1”, which does not correspond to a recognized public‑trusted authority and further suggests a low‑quality or self‑signed deployment. As of the report date the domain has been taken offline, and no active HTTP response was observed during verification. The available evidence points to a short‑lived generic phishing infrastructure that leveraged Cloudflare’s CDN to obscure the origin of the malicious site.
Uncertainty remains regarding the exact phishing payload, target brand, or credential‑harvesting technique because the page content was not captured beyond the title. Defenders should continue to block the domain at network perimeter and update URL filtering lists, monitor for re‑registration of the same name or related subdomains, and consider adding the IP address 188.114.97.3 to deny‑list rules, especially for outbound traffic destined for Cloudflare edge nodes that have been associated with malicious activity. Ongoing observation of the IP and any future DNS records is recommended to detect potential resurrection of the campaign.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
9 monitored external feeds No match
Forensic Intelligence
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive