The domain rainbetapp.info was registered on 08 January 2026 through Dynadot Inc and is currently resolving to the IPv4 address 69.165.75.129. The authoritative name servers ns1.dyna-ns.net and ns2.dyna-ns.net are typical of Dynadot's default DNS configuration. Within days of its creation the domain appeared on three public blocklists and has been actively blocked by the PhishDestroy, MetaMask, and SEAL filtering services. VirusTotal records show that three of ninety‑one scanned security vendors have flagged the domain as malicious, confirming that at least a subset of scanners recognize it as a phishing host.
The threat is classified as generic phishing, and the status remains active as of the 28 July 2026 assessment. Publicly available evidence does not include a page title, SSL certificate details, HTTP response codes, or any observed brand impersonation, limiting the depth of content‑level analysis. Consequently, the exact payload or credential‑harvesting technique employed by the site cannot be confirmed at this time. Nonetheless, the combination of recent creation, rapid blocklist inclusion, and multiple vendor detections provides sufficient confidence to treat the domain as high‑risk.
Defenders should add rainbetapp.info to DNS and URL filtering policies, block the associated IP address 69.165.75.129 at network perimeters, and monitor for any outbound connections to the domain or its name servers. Continuous re‑scanning on VirusTotal or similar platforms is recommended to capture any changes in detection status. Organizations that employ email gateways or web proxies should ensure that the domain is explicitly denied to prevent credential capture attempts.