Analysis of the domain pobex.cfd, created on July 27 2026 and hosted on Cloudflare nameservers daphne.ns.cloudflare.com and thaddeus.ns.cloudflare.com, shows an active threat posture. The domain resolves to the IP address 172.67.183.210, a Cloudflare‑owned address that is commonly leveraged for fast‑flux or proxy‑based abuse. VirusTotal records indicate that the domain has been scanned by 91 antivirus and URL‑reputation vendors; none have generated a detection at the time of review. While the lack of detections does not equate to a clean bill of health, it suggests that the payload, if any, has not yet been captured by existing signatures.
The domain is listed on a single external security blocklist and has been explicitly blocked by the PhishDestroy filtering service, confirming that at least one remediation platform has identified it as malicious. Registration data points to Global Domain Group LLC as the registrar, offering no immediate clues about the operator’s identity. No public page title, SSL certificate details, or HTTP response codes are available, leaving the content and exact phishing vector unverified.
Given the combination of recent registration, Cloudflare hosting, presence on a blocklist, and active status, defenders should treat pobex.cfd as a high‑confidence phishing indicator. Recommended actions include adding the domain to network‑level deny lists, monitoring DNS queries for the 172.67.183.210 address, and configuring web‑filtering solutions to block any HTTP requests to pobex.cfd. Continuous re‑scanning on VirusTotal and other sandbox services is advised to capture potential payload evolution.