The domain drgn50.com was registered on July 11 2026 through Global Domain Group LLC and remains active as of the report date (July 28 2026). Its authoritative name servers are eugene.ns.cloudflare.com and faye.ns.cloudflare.com, indicating the use of Cloudflare’s DNS service. DNS resolution points to the IPv4 address 212.86.126.181, which is the sole host observed for this domain.
The infrastructure has been flagged by the PhishDestroy blocklist and appears on one additional security blocklist, suggesting that at least one trusted threat‑intelligence feed considers the domain malicious. VirusTotal has processed the domain with 91 antivirus or URL‑reputation engines, none of which returned a detection; however, the absence of a detection does not constitute evidence of safety. No public SSL certificate details, HTTP response codes, page titles, or brand‑specific references have been disclosed, leaving the content of the site unverified.
The combination of recent creation, Cloudflare‑based hosting, a single IP address, and inclusion on a phishing‑focused blocklist aligns with patterns commonly observed in generic phishing infrastructure. Defenders should treat drgn50.com as high‑risk: block network traffic to the domain and its resolved IP, monitor DNS queries for future resolution changes, and consider adding the domain to internal deny lists. Continuous re‑evaluation is advised, as additional telemetry (e.g., payload analysis, URL redirects, or user reports) may emerge to clarify the threat’s exact scope.