Analysis indicates that rainbetrun.info is currently active and has been classified as a generic phishing site. The domain was registered on January 08, 2026 through Dynadot Inc and uses the authoritative nameservers ns1.dyna-ns.net and ns2.dyna-ns.net. DNS resolution points to the IPv4 address 69.165.75.129, which is the sole host observed for this indicator. Reputation data shows the domain appears on three security blocklists and has been explicitly blocked by PhishDestroy, MetaMask, and SEAL, confirming its malicious intent.
VirusTotal scans report that four of ninety‑one security vendors have flagged the domain, reinforcing the phishing assessment. No additional telemetry such as SSL certificates, HTTP response codes, or page titles is currently available, leaving the surface‑web content uncharacterised. The limited but consistent signals from multiple independent sources suggest a high risk to users who may encounter the domain in email or social‑media campaigns. Defenders should prioritize immediate containment: add rainbetrun.info to network‑level deny lists, enforce DNS sink‑holing, and ensure endpoint protection solutions reference the latest blocklist feeds that include this indicator.
Continuous monitoring of the IP address 69.165.75.129 for new associations is advised, as well as periodic re‑scans to capture any changes in payload or hosting. Because the registrar and nameserver infrastructure are publicly known, threat‑intel teams may also consider contacting Dynadot for potential abuse mitigation. Until further forensic evidence is obtained, the domain should be treated as a high‑confidence phishing threat.