Analysis of line.truebnb.org, observed on 31 July 2026, shows that the domain was registered on 12 June 2026 through Fewmoretaps OU d/b/a Trustname.com and is served by the authoritative nameservers ares.trustname.com and zeus.trustname.com. The domain resolves to the IPv4 address 91.229.239.28. VirusTotal records indicate that the domain has been scanned by 91 security vendors, and none of those vendors have raised a detection at the time of observation.
The domain is currently listed on a single external blocklist, PhishDestroy, which has actively blocked resolution attempts. No additional public blocklists, Safe Browsing entries, or Open Threat Exchange (OTX) references are present in the supplied intelligence. The limited evidence suggests a generic phishing campaign, but the specific lures, credential‑stealing pages, or targeted brands have not been disclosed.
The short age of the domain (approximately seven weeks) and the use of a reputable‑looking registrar may be intended to evade reputation‑based filters. Defenders should consider immediate network‑level blocking of both the domain and its resolving IP, incorporate the nameservers into threat‑intel feeds for correlation, and continue to monitor for any changes in detection status or additional blocklist listings. Ongoing analysis of HTTP responses, SSL certificates, and page content is recommended to confirm the phishing payload and to enrich attribution.