This domain, sharkhub.org, was registered on 21 May 2026 through Fewmoretaps OU doing business as Trustname.com. The authoritative name servers are candy.ns.cloudflare.com and javon.ns.cloudflare.com, indicating the use of Cloudflare’s DNS infrastructure. DNS resolution points to the IPv4 address 188.114.97.3, a host that is currently reachable and listed as active. VirusTotal has processed the domain with 91 distinct scanning engines; none of those engines reported a detection at the time of analysis. While the lack of a detection does not constitute assurance of legitimacy, it demonstrates that the domain has not yet triggered a signature match in the examined vendor set.
The domain is present on a single public blocklist and is explicitly blocked by the PhishDestroy service, which classifies it as a phishing resource. No additional public blocklists, Safe Browsing listings, or Open Threat Exchange (OTX) entries were observed in the available data. The registrar information, name‑server configuration, and IP address together suggest a typical abuse pattern where threat actors leverage reputable DNS providers to obtain reliable resolution while hosting malicious content on shared infrastructure. The recent creation date, combined with the blocklist entry, aligns with the observed “generic phishing” threat type.
Defenders should treat sharkhub.org as a high‑confidence indicator of phishing activity. Recommended actions include adding the domain and its resolving IP address to network‑level deny lists, updating web‑proxy and DNS filtering rules, and monitoring for any outbound connections to the host. Continuous re‑scanning on VirusTotal and periodic checks against emerging blocklists are advised to capture any future detections. Incident response teams should also consider correlating internal logs for traffic to this domain to identify potential compromised accounts or credential‑stealing attempts.