This report analyzes the domain program.referral-arcus.com, which is flagged for generic phishing activity as of July 31, 2026. The domain was created on July 20, 2026, and remains active at the time of writing. It is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar not commonly associated with legitimate enterprise operations. The domain resolves to IP address 188.114.96.3, which is part of Cloudflare's hosting infrastructure, as confirmed by the nameservers candy.ns.cloudflare.com and julio.ns.cloudflare.com. The use of Cloudflare may provide anonymity for the operators, complicating takedown efforts.
Current threat intelligence indicates that program.referral-arcus.com appears on one security blocklist, specifically PhishDestroy. This listing suggests that at least one independent source has identified the domain as malicious or associated with phishing campaigns. No other detection vendors have reported on this domain, and it has not been assessed by Google Safe Browsing or AlienVault OTX at this time. The absence of additional vendor data does not confirm safety; rather, it reflects the domain's recent creation and limited exposure. The domain's exact page content has not yet been analyzed, so the specific lure, branding, or login mechanism remains unknown. Analysts should treat this domain as a likely phishing infrastructure based on the blocklist hit and the generic threat classification.
Defenders are advised to block access to program.referral-arcus.com and its parent domain referral-arcus.com at the DNS or proxy level to prevent user exposure. Since the domain is still active, monitor for changes in IP resolution, nameserver modifications, or new subdomains that may indicate campaign evolution. Email gateways should flag any messages containing links to this domain, as phishing campaigns often use such newly registered domains in credential-harvesting attacks.