Analysis of the domain strobefi-update.live, created on July 02, 2026 and registered through Dynadot Inc., shows that it is currently active and resolves to the Cloudflare‑owned address 188.114.97.3 located in California, United States. The domain is served by Cloudflare nameservers diana.ns.cloudflare.com and nash.ns.cloudflare.com, indicating the use of a reputable CDN for traffic obfuscation. Multiple threat intelligence feeds have flagged the domain: it appears on three security blocklists and is listed as blocked by the PhishDestroy, MetaMask, and SEAL filtering services.
VirusTotal scans have returned detections from eleven out of ninety‑one antivirus and URL‑reputation engines, reinforcing the malicious classification. The primary observed threat type is credential phishing, as indicated by the supplied classification. No public page title or SSL certificate details have been released, so the exact content of the hosted site remains unverified, but the presence of detections across independent vendors suggests a high likelihood of credential‑stealing payloads.
Defenders should add 188.114.97.3 to network‑level deny lists, enforce DNS filtering for strobefi-update.live, and monitor outbound connections to Cloudflare edge nodes that resolve to this address. Continuous re‑scanning of the domain on VirusTotal and inclusion in internal threat‑intel feeds are recommended to capture any changes in detection scores. Because the domain is only weeks old, rapid propagation is possible; organizations should treat any user‑initiated traffic to this domain as malicious and educate users about the risk of unsolicited credential requests.