Analysis of web3-support.net indicates a newly created malicious infrastructure supporting a generic phishing campaign. The domain was registered on June 30, 2026 through Ultahost, Inc. and is currently active. DNS resolution points to the IP address 188.114.97.3, and the authoritative name servers are april.ns.cloudflare.com and yadiel.ns.cloudflare.com, both associated with Cloudflare's DNS service. VirusTotal records show that eight out of ninety‑one security vendors have flagged the domain, suggesting observable malicious characteristics despite the limited detection coverage.
The domain appears on a single public blocklist, PhishDestroy, confirming that at least one anti‑phishing consortium has taken remediation action. No additional blocklist entries, Safe Browsing alerts, or Open Threat Exchange (OTX) reports are presently documented. Details such as SSL certificate validity, HTTP response codes, page title, or any observed brand targeting have not been disclosed, leaving the exact content and phishing lure undefined.
Consequently, defenders should treat the domain as high‑risk, enforce network‑level blocking, and incorporate the IP address 188.114.97.3 into threat‑intel feeds. Continuous monitoring of DNS queries and outbound connections to the listed Cloudflare name servers is advised, as is periodic re‑scanning of the domain to capture any evolving indicators. In the absence of concrete page‑level evidence, precautionary containment remains the recommended mitigation approach.