Analysis of jimothytokens.com indicates that the domain was created on July 17, 2026 and is currently resolved to the IPv4 address 172.67.157.16. The domain is serviced by a mixed set of authoritative name servers—deborah.ns.cloudflare.com, uriah.ns.cloudflare.com, ns1.google.com, and ns2.google.com—suggesting the use of both Cloudflare and Google DNS infrastructure. Registration was performed through Dominet (HK) Limited, a registrar based in Hong Kong, which is consistent with the observed registration pattern for recent phishing infrastructure.
VirusTotal records show that the domain has been scanned by 91 vendors; none have issued a detection at the time of this report, though the lack of detections does not constitute validation of benign intent. The domain is listed on one external security blocklist and is actively blocked by the PhishDestroy service, confirming that at least one security vendor has classified it as malicious. The operational status is marked as active and the threat is categorized as generic phishing, with the overall risk level noted as under investigation.
No public web content, page title, or brand targeting information has been disclosed, leaving the precise phishing payload and lure unknown. Defenders should incorporate the domain and its resolved IP address into outbound filtering rules, monitor DNS queries for the listed name servers, and consider adding the domain to internal blocklists. Continuous re‑evaluation is advised, as future vendor analyses or additional blocklist appearances may provide further context on the campaign’s evolution.