This domain, au-rainbet.com, is flagged as a high‑risk generic phishing site as of July 28 2026. The domain was created on March 30 2026 and is registered through Namecheap Inc. Its authoritative nameservers are dara.ns.cloudflare.com and lou.ns.cloudflare.com, and DNS resolution points to the IP address 188.114.97.3. The domain appears on three independent security blocklists—PhishDestroy, MetaMask, and SEAL—which indicates that multiple threat‑intelligence feeds have observed malicious activity associated with it.
VirusTotal has recorded three positive detections out of ninety‑one submitted security vendors, confirming that at least a small subset of scanners recognize the domain as malicious. The unique seed identifier e415bd links this observation to other internal records, reinforcing the consistency of the intelligence. The available evidence does not include details about the hosted content, SSL certificate, HTTP response codes, or page title, so the exact phishing vector employed by the site remains unknown.
However, the convergence of recent registration, Cloudflare DNS infrastructure, presence on multiple blocklists, and multiple vendor flags provides a strong indication that the domain is being used for credential‑stealing or fraudulent activity. Defenders should proactively block or sinkhole au-rainbet.com at the network perimeter, add the IP address 188.114.97.3 to deny‑list rules, and monitor for any outbound connections to this host. Continuous re‑scanning with updated threat‑intel platforms is recommended to capture any changes in detection rates or additional indicators of compromise.