On July 31, 2026, analysis of the domain theblackbullsol.live was performed following reports of generic phishing activity. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and its creation date is recorded as July 26, 2026. DNS resolution points to the IP address 188.114.97.3, which is hosted on Cloudflare infrastructure indicated by the authoritative nameservers olivia.ns.cloudflare.com and stan.ns.cloudflare.com. The domain currently appears on one public security blocklist and is explicitly blocked by the PhishDestroy service, confirming that at least one sinkhole has taken action against it.
VirusTotal has processed the domain with 91 scanning engines; none reported a detection, but the lack of a positive result is not evidence of legitimacy. No additional intelligence such as page title, SSL certificate details, or HTTP response codes is available, leaving the content and exact phishing payload unknown. The limited visibility suggests the threat actor may be using a short‑lived domain to host a credential‑harvesting page, a pattern commonly observed in fast‑flux campaigns.
Defenders should add the domain to local deny lists, monitor DNS queries for the IP 188.114.97.3, and enforce outbound filtering for connections to Cloudflare name servers that resolve to this address. Continuous re‑scanning with multiple sandboxes is recommended to capture any later payload changes. Until further forensic evidence is gathered, the domain remains classified as an active phishing infrastructure under investigation.