The domain ca-rainbet.com was registered on March 30, 2026 through the registrar Namecheap Inc. It is currently active and resolves to the IP address 172.67.196.50, which is owned by Cloudflare. The authoritative nameservers are brit.ns.cloudflare.com and clay.ns.cloudflare.com, a common configuration for short‑lived malicious sites that rely on Cloudflare’s CDN and DNS services. VirusTotal scans have recorded three detections out of ninety‑one security vendors, indicating that at least a subset of scanners consider the domain malicious.
The domain also appears on three independent security blocklists and is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filters, reinforcing its classification as a phishing resource. No public page title, SSL certificate details, HTTP status codes, or Safe Browsing entries were available at the time of analysis, so the exact content served by the site remains unverified. The combination of a recent creation date, Cloudflare hosting, multiple blocklist listings, and vendor detections aligns with typical infrastructure used for generic phishing campaigns.
Defensive recommendations include adding ca‑rainbet.com to network and endpoint deny lists, monitoring DNS queries for the associated Cloudflare IP, and enforcing URL filtering rules that reference the known blocklists. Continuous re‑evaluation with updated VirusTotal scans and sandbox analysis is advisable to capture any evolving payloads. Given the domain’s active status as of July 28, 2026, immediate mitigation is warranted to prevent user exposure.