fun100x[.]network
fun100x.network was registered on February 21, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The domain resolves to the IP address 104.21.20.199, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. Nameserver resolution points to earl.ns.cloudflare.com and melody.ns.cloudflare.com, confirming that the domain is fronted by Cloudflare’s edge network and is served over HTTP/3. The only HTTP response observed is a 403 status code, and the TLS handshake terminates with a certificate issued by Google Trust Services under the label WE1. The page title returned by the server is “Just a moment…”, which is a generic placeholder often used by Cloudflare challenge pages. No additional content was captured, so the exact phishing payload cannot be confirmed at this time. Threat intelligence flags the domain as a generic phishing site. It appears on a single security blocklist and has been explicitly blocked by PhishDestroy. Independent scoring systems show a Gridinsoft trust score of 0 out of 100, and VirusTotal reports a single security vendor flagging the domain. The combination of a newly created domain, use of Cloudflare protection, and a low trust score aligns with typical infrastructure choices observed in phishing campaigns. Because the underlying page content has not been disclosed, the specific brand or credential‑harvesting technique remains uncertain. However, the presence of a Cloudflare challenge page, a 403 response, and the “Just a moment…” title indicate an attempt to hide malicious redirects behind a short‑lived verification step. Defenders should continue to block the domain at perimeter filters, monitor DNS queries for the associated IP address, and incorporate the domain into threat‑intel feeds. Ongoing observation is recommended to capture any future payload changes.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive