The domain powelballen.com was registered on 21 July 2026 and is currently resolving to 172.67.155.66, a Cloudflare‑hosted address served by the authoritative nameservers jasper.ns.cloudflare.com and ziggy.ns.cloudflare.com. The registrar information lists Fewmoretaps OU d/b/a Trustname.com. Within a day of creation the domain was added to a security blocklist and is actively blocked by the PhishDestroy feed, indicating that at least one feed has classified the site as malicious. VirusTotal records show that the domain has been scanned by 91 anti‑malware vendors; none have raised a detection, but the absence of a flag does not constitute a safety assurance.
No public evidence has been disclosed regarding the site’s SSL certificate, HTTP response codes, page title, or any associated malware kits, leaving those vectors unverified. The limited visibility suggests that the threat actor may be leveraging a newly minted domain to host a generic phishing campaign, possibly targeting credential harvest or credential‑replay scenarios. Because the infrastructure relies on Cloudflare, the IP address is shared among many unrelated tenants, complicating direct attribution based on network traffic alone.
Defenders should immediately add powelballen.com to DNS blocklists and outbound filtering rules, monitor for outbound connections to 172.67.155.66, and enforce strict email and web gateway controls to prevent user interaction with the domain. Continuous re‑scanning on VirusTotal or similar platforms is recommended to capture any future detections. Until additional forensic data such as page content, SSL fingerprint, or malware payloads become available, the domain should be treated as high‑risk and its traffic should be quarantined or dropped.