This domain, rainbet-ro.eu.com, is currently active and has been identified as part of a credential‑harvesting operation. The authoritative name servers are bowen.ns.cloudflare.com and josephine.ns.cloudflare.com, indicating that the infrastructure is hosted behind Cloudflare’s DNS and edge services. DNS resolution points to the IP address 188.114.96.3, which is allocated to Cloudflare and commonly used for fast‑flux or proxy‑based phishing sites. The domain appears on three independent security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple threat‑intelligence feeds have flagged it as malicious.
VirusTotal analysis shows that three out of ninety‑one scanning engines have generated a detection, reinforcing the suspicion despite the limited coverage. No public SSL certificate details, HTTP response codes, or page‑title information are available in the current intelligence set, and the registrar or registration date have not been disclosed. The absence of these data points does not diminish the risk; the observed indicators already satisfy a high‑confidence threshold for credential‑theft activity.
Defenders should add rainbet-ro.eu.com to URL filtering rules, enforce DNS sink‑holing, and update endpoint protection signatures to include the known blocklist entries. Continuous monitoring of Cloudflare‑owned IP ranges for new domains resolving to 188.114.96.3 is advisable, as adversaries often recycle the same hosting substrate. Threat‑hunting teams should also query recent phishing‑reporting feeds for any payload or credential‑submission URLs that reference this domain, and consider sharing newly observed artifacts with industry‑wide sharing platforms to accelerate collective detection.