Analysis of himgajria.free-drop.fun shows a newly registered domain (creation date July 28, 2026) hosted on Cloudflare infrastructure. The registrar is listed as NICENIC INTERNATIONAL GROUP CO., LIMITED, and the authoritative nameservers are brynne.ns.cloudflare.com and rudy.ns.cloudflare.com, resolving to IP address 188.114.96.3. The domain appears on a single public blocklist and is actively blocked by PhishDestroy, indicating that at least one security feed has classified it as malicious.
VirusTotal records reveal that the domain was scanned by 91 antivirus and URL‑reputation vendors; none of the scanners reported a detection at the time of analysis, but the absence of detections does not constitute a safety guarantee. The domain’s risk level remains under investigation, and its status is marked as active, suggesting ongoing or potential use in phishing campaigns. Defenders should consider immediate mitigation steps: add the domain and its resolving IP to outbound filtering rules, incorporate the domain into internal blocklists, and monitor DNS queries for repeated resolution attempts.
Continuous re‑scanning on VirusTotal or similar platforms is advised, as detection signatures may evolve. Given the recent registration and the lack of historical reputation, the domain should be treated as a high‑confidence phishing indicator until further intelligence clarifies its operational scope.