Analysis of rain-bet.nl, first observed on a security blocklist and currently listed by PhishDestroy, indicates that the domain is being used for a generic phishing campaign. The domain was registered through Registrar.eu on October 24, 2025 and is hosted on Cloudflare infrastructure, as evidenced by the authoritative nameservers dave.ns.cloudflare.com and eva.ns.cloudflare.com and the resolved address 172.67.222.241. The domain has been scanned by 91 VirusTotal vendors, none of which reported a detection at the time of analysis; this lack of detections does not constitute a safety assurance.
The domain remains active, and no additional public intelligence such as Safe Browsing verdicts, OTX tags, or SSL certificate details have been published. Because the site’s content, page title, and target brand have not been disclosed, the precise phishing lure cannot be described, but the classification as a generic phishing operation is supported by its inclusion on known blocklists.
Defenders should consider adding rain-bet.nl to DNS and proxy blocklists, monitoring for any resolution changes, and employing sinkholing or traffic redirection where appropriate. Continuous re‑evaluation is advised, as the infrastructure could be repurposed or expanded, and further evidence may emerge from future scans or threat‑intel feeds.