The domain jojobet8230.icu was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and first observed on July 27, 2026. It is hosted on Cloudflare infrastructure, as indicated by the authoritative name servers chris.ns.cloudflare.com and gail.ns.cloudflare.com, and resolves to the IPv4 address 104.21.59.22. The domain appears on one security blocklist and is actively blocked by the PhishDestroy filtering service. VirusTotal submitted the domain to 91 scanning engines; none of the engines reported a detection at the time of analysis, which does not imply that the domain is benign.
The available intelligence classifies the activity as a generic phishing campaign, although no additional context such as targeted brand, page title, or payload details have been publicly disclosed. Analysis confirms that the domain remains active as of the report date, July 31, 2026. The lack of publicly available page content limits the ability to assess the specific lure or credential‑harvesting mechanism employed.
Defenders should continue to enforce blocking of the domain and its resolving IP address, incorporate the domain into local and cloud‑based URL filtering policies, and monitor for any future changes in detection status on aggregators such as VirusTotal. Ongoing observation of DNS records for additional name‑server changes or new IP assignments is recommended. Because the domain is hosted on a shared CDN, any abrupt takedown may be challenging; therefore, threat‑intel sharing with upstream providers and rapid rule updates in intrusion‑prevention systems will help mitigate exposure while additional investigation is pursued.