The domain jojobet-jojobetgiris.icu was registered on July 26, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and remains active as of the report date, July 31, 2026. DNS resolution points to the IPv4 address 188.114.97.3, and the authoritative name servers are chris.ns.cloudflare.com and gail.ns.cloudflare.com, indicating use of Cloudflare’s DNS infrastructure. The domain appears on a single security blocklist and is currently blocked by the PhishDestroy service, suggesting that at least one anti‑phishing provider has taken protective action against it. VirusTotal analysis shows that four of ninety‑one scanning engines have flagged the domain, providing modest but notable detection confidence.
No additional public reputation scores, SSL certificate details, or HTTP response codes are available in the supplied intelligence. The limited detection footprint, combined with the recent registration date, points to a fast‑flux style deployment typical of credential‑stealing operations that aim to exploit the short window between domain creation and takedown. Defenders should immediately add jojobet-jojobetgiris.icu to network and endpoint allow‑lists that block outbound connections to the resolved IP address 188.114.97.3, and enforce DNS filtering to prevent resolution of the domain.
Monitoring of the associated Cloudflare name servers for newly created sibling domains may reveal further campaign expansion. Organizations using web‑proxy or secure web‑gateway solutions should ensure that the domain is included in URL filtering policies, and security information and event management (SIEM) rules should be tuned to alert on any outbound traffic to this FQDN or its IP. Continuous re‑evaluation of VirusTotal and other multi‑engine scanners is advised, as additional detections may emerge as the campaign matures.