Analysis of faceit-verifying.com indicates an active credential‑phishing infrastructure. The domain was registered on 30 June 2026 through Global Domain Group LLC and currently resolves to the IPv4 address 188.114.97.3. DNS resolution is delegated to the Cloudflare name servers alexa.ns.cloudflare.com and dimitris.ns.cloudflare.com, suggesting the operator is leveraging Cloudflare’s CDN and DDoS mitigation services. The domain is listed on one public security blocklist and is actively blocked by the PhishDestroy feed, confirming that threat‑intel communities have observed malicious activity associated with it.
VirusTotal scans show that 12 of 91 antivirus and URL‑reputation engines flag the domain as malicious, providing independent corroboration of its phishing nature. No additional infrastructure details such as autonomous system number, hosting country, SSL certificate metadata, or HTTP response codes are available from the current intelligence set. Likewise, page‑title information, brand‑target identification, or evidence of a specific phishing kit has not been disclosed, leaving the exact victim‑facing content unverified. Nevertheless, the convergence of recent registration, use of reputable DNS providers, presence on a dedicated phishing blocklist, and multi‑engine detection strongly suggests a purpose‑built credential‑phishing campaign.
Defenders should add faceit-verifying.com to network and endpoint blocklists, deny outbound connections to its resolved IP address, and monitor Cloudflare‑served DNS queries for the domain. Because the domain leverages Cloudflare, the underlying hosting infrastructure may be shared with benign sites; therefore, any active response should be limited to domain‑level blocking rather than blanket IP blacklisting to avoid collateral impact. Continuous re‑evaluation is advised, as future scans may reveal additional indicators such as SSL fingerprints, HTTP status codes, or malicious payloads that could refine mitigation actions.