omnipool[.]top
“Attention Required! | Cloudflare”
Analysis of www.omnipool.top shows a domain created on 12 March 2026 and immediately pointed at the Cloudflare edge IP 188.114.97.3 (AS13335, United States). The domain uses Cloudflare’s DNS service (maisie.ns.cloudflare.com, tosana.ns.cloudflare.com) and presents the generic Cloudflare “Attention Required!” page title, indicating that the site is currently offline. The SSL certificate is issued by Google Trust Services under the WE1 root, which is a legitimate certificate authority and therefore does not imply trustworthiness of the hosted content. Registration was performed through Gname.com Pte. Ltd., a registrar commonly used for both legitimate and malicious registrations.
The domain is classified as a generic phishing campaign with a specific investment‑scam focus, and it has been listed by the PhishDestroy blocklist. VirusTotal records show that 13 of 91 security vendors have flagged the domain as malicious, and it appears on one additional security blocklist. Technologies detected include Cloudflare Browser Insights and the standard Cloudflare reverse‑proxy stack, which are often leveraged by threat actors to hide origin infrastructure. The combination of a recent registration date, use of a widely trusted CDN, a legitimate‑looking SSL certificate, and multiple vendor detections strongly suggests malicious intent despite the current offline status.
Uncertainty remains regarding the exact payload or phishing landing page, as no content has been captured. Defenders should continue to block the domain at network perimeter, monitor DNS queries for re‑registration, and consider adding the IP address to threat‑intel feeds. Ongoing observation of related Cloudflare‑protected domains registered through the same registrar may reveal a broader campaign.
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 sources · synchronized Aug 9, 2026
Detection timeline
Stored observations in chronological order.
-
VirusTotal
VirusTotal: 0 → 1
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of omnipool.top · checked Mar 12, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive