rewards-fomo[.]family
Analysis as of July 29 2026 indicates that the domain rewards-fomo.family was registered on June 12 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and currently resolves to the IP address 104.21.30.163. The domain appears on three public security blocklists and is actively blocked by the PhishDestroy, MetaMask, and SEAL filtering services, suggesting that multiple downstream security products have already identified it as malicious. VirusTotal scans show that five of ninety‑one antivirus or URL‑analysis engines have flagged the domain, reinforcing the suspicion of malicious activity despite the limited detection count.
The threat is classified as generic phishing, and the elevated risk rating reflects the combination of recent registration, active blocklist presence, and partial vendor detections. No public information is available regarding SSL certificate details, HTTP response codes, page title, or the exact phishing payload, leaving the precise luring technique uncertain.
Defenders should prioritize blocking or sinkholing the domain at the network perimeter, update proxy and DNS filtering policies to include the three known blocklists, and ensure endpoint security solutions incorporate the latest threat intelligence feeds that reference rewards-fomo.family. Continuous monitoring of the associated IP address for anomalous traffic and periodic re‑scanning with multi‑vendor services are recommended to capture any evolution in the payload or additional detections.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive