The domain us-33autosales.com was registered on 27 July 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and uses Cloudflare authoritative name servers april.ns.cloudflare.com and lloyd.ns.cloudflare.com. The domain resolves to the IPv4 address 188.114.97.3, which is hosted on Cloudflare's network. No additional hosting details such as ASN or country are provided in the current intel. The domain was first observed on the same day as its creation, and its status remains active as of the report date 31 July 2026.
VirusTotal has processed the domain with 91 scanning engines, none of which returned a detection at the time of analysis. While the lack of detections may indicate that the payload or page content has not yet been identified by the vendors, the result does not constitute a safety assurance. The domain is listed on a single public security blocklist and is actively blocked by the PhishDestroy service, confirming that at least one downstream defense has classified it as malicious. Given the classification of “generic phishing” in the intelligence feed, the domain is presumed to be used for credential‑harvesting or information‑stealing campaigns, although the exact target brand or service has not been disclosed.
The short lifespan between registration and first appearance, combined with the use of Cloudflare’s edge infrastructure, aligns with typical phishing‑as‑a‑service patterns that leverage reputable CDNs to evade reputation‑based filters. Defenders should add 188.114.97.3 to network‑level deny lists, monitor DNS queries for us-33autosales.com, and enforce URL filtering rules that block the domain across web proxies and endpoint browsers. Continuous re‑scanning on VirusTotal or similar multi‑engine platforms is recommended to capture any future payload changes. Organizations should also consider sharing observed traffic with threat‑intel sharing communities to improve collective detection of this emerging indicator.