Analysis of faceit.integrate-2fa.com as of July 30, 2026 indicates that the domain is actively used in a generic phishing campaign. The domain was registered on November 6, 2025 through Dominet (HK) Limited, a registrar known to host a variety of short‑lived malicious sites. It is delegated to Cloudflare nameservers brad.ns.cloudflare.com and val.ns.cloudflare.com, which provide CDN and DDoS mitigation services but also obscure the true origin of the hosting infrastructure. DNS resolution points to the IPv4 address 188.114.97.3, an address that is currently listed on at least one public security blocklist and has been tagged by the PhishDestroy blocklist as malicious.
The domain has been submitted to VirusTotal and examined by 91 scanning engines; none of the engines reported a detection at the time of the scan, however the absence of detections does not confirm benign intent. The domain appears on a single additional blocklist, suggesting limited but existing exposure in threat‑intel feeds. No public SSL certificate details, HTTP response codes, Safe Browsing verdicts, OTX references, or page‑title metadata have been disclosed, leaving those aspects unverified.
Given the combination of recent registration, use of a reputable CDN to hide location, presence on a known phishing blocklist, and lack of any visible defensive signals, the domain should be treated as high‑risk for credential‑stealing activity. Defenders are advised to add 188.114.97.3 and the full hostname to outbound filtering rules, monitor DNS queries for the domain, and ensure that any user‑facing authentication flows that reference “integrate‑2fa” are validated against official sources. Continuous re‑evaluation is recommended as additional telemetry becomes available.