rainbet.com.mx was registered on February 26, 2026 through Dynadot Inc. The domain resolves to the Cloudflare‑owned address 104.21.1.101 and uses the Cloudflare authoritative nameservers corey.ns.cloudflare.com and teresa.ns.cloudflare.com. VirusTotal reports that four of ninety‑one scanned security vendors have flagged the domain, indicating the presence of malicious indicators. Independent blocklist services PhishDestroy, MetaMask and SEAL have already added the domain to their deny lists, and it appears on three additional public security blocklists, reinforcing its classification as a high‑risk phishing resource.
The current operational status is active; the domain is still reachable and continues to host content associated with a generic phishing campaign. No public SSL certificate details, HTTP response codes, or page‑title information have been released, so the exact lure and credential‑harvesting mechanisms remain unknown. However, the combination of recent registration, Cloudflare hosting, multiple vendor detections, and blocklist listings provides sufficient confidence for defensive actions.
Defenders should immediately block rainbet.com.mx at network perimeter and DNS layers, monitor outbound connections to the 104.21.1.101 address, and consider sinkholing or redirecting traffic to a safe‑browse warning page. Ongoing threat‑intel feeds should be consulted for any future attribution updates or observed payloads linked to this infrastructure. Because the domain is freshly created and already flagged by several security products, rapid containment is advised to prevent credential theft or further propagation of the phishing campaign.