Analysis of the domain zotabi.click, created on July 23, 2026, shows a short operational window typical of newly‑registered phishing infrastructure. The domain is hosted on Cloudflare’s network, using the nameservers chloe.ns.cloudflare.com and jermaine.ns.cloudflare.com, and resolves to the IPv4 address 178.16.54.253. Registration was performed through Dynadot, LLC, a registrar known for rapid provisioning of bulk domains.
The domain currently appears on a single public blocklist, PhishDestroy, indicating that at least one security‑vendor has identified it as malicious and taken remediation steps. VirusTotal records demonstrate that the domain has been scanned by 91 antivirus and URL‑reputation engines, none of which have issued a detection at the time of this report; however, the absence of a detection does not constitute a validation of safety and should not be interpreted as a risk reduction. The limited visibility—no additional blocklist listings, no public SSL or HTTP status data, and no disclosed page title or brand targeting—means that the full scope of the campaign remains uncertain.
Defenders should treat zotabi.click as a high‑confidence phishing indicator, block the domain at network perimeters, update URL filtering policies, and monitor for any emergence of related indicators such as additional IPs, new hostnames, or observed payloads. Continuous re‑evaluation is recommended, as the infrastructure may evolve quickly given the recent registration date.