rainbetindia.info was registered through Dynadot Inc on 8 January 2026 and is currently pointed at the IPv4 address 69.165.75.129. The domain is served by the authoritative name servers ns1.dyna-ns.net and ns2.dyna-ns.net, both of which are typical of dynamically allocated hosting. Within days of its creation the domain appeared on three independent security blocklists and has been explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services. VirusTotal scans show that three of ninety-one antivirus or URL-reputation engines have raised a detection for the domain, confirming that at least some security products consider it malicious. The threat classification supplied in the intake data is "generic phishing," and the risk rating is high.
The domain remains active as of the report date, 28 July 2026, and no evidence of takedown or remediation has been observed. From the available data the primary indicators of compromise are the domain name itself, the hosting IP address, and the two dyna-ns name servers. No TLS certificate details, HTTP status codes, page titles, or content hashes have been released, so the exact phishing landing page cannot be described. Consequently, defenders cannot assess whether the site mimics a particular brand or employs a known phishing kit. The lack of public page metadata means that detection must rely on network-level and reputation-based controls.
Defenders should immediately add rainbetindia.info to DNS-based blocklists and enforce outbound filtering that denies connections to 69.165.75.129. Where possible, the associated name servers ns1.dyna-ns.net and ns2.dyna-ns.net should be added to a deny list for new registrations, as they are frequently used by transient malicious infrastructure. Monitoring for newly resolved subdomains under the same IP range is recommended, as the operators may reuse the hosting environment for additional phishing campaigns.