Analysis of blocxhub.info shows that the domain was registered on May 10, 2026 through GNAME.COM PTE. LTD. and is hosted on the Cloudflare network, using the authoritative name servers paloma.ns.cloudflare.com and vasilii.ns.cloudflare.com.
DNS resolution returns the address 188.114.96.3, which is an IP known to be shared among other malicious actors and is currently listed on three public security blocklists. Independent scanning services have flagged the domain on two of ninety‑one VirusTotal engines, indicating that at least a minority of antivirus products have identified malicious behavior associated with the host. The domain is also listed in the blocklists maintained by PhishDestroy, MetaMask, and SEAL, reinforcing its classification as a phishing‑related resource.
While the available data confirm that blocxhub.info is actively being used for a generic phishing campaign, no additional intelligence such as page titles, SSL certificate details, or observed HTTP response codes has been released, leaving the exact content and lure techniques undisclosed. Defenders should continue to block connections to the resolved IP 188.114.96.3, enforce DNS‑level denial for the domain, and update endpoint and email security policies to include the identified blocklist entries. Continuous monitoring of the domain’s DNS records and any future VirusTotal submissions is recommended to capture potential changes in payload or hosting infrastructure.