The domain rarelocker.com was registered on May 11, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently hosted at IP address 158.94.211.169. DNS resolution is delegated to the authoritative name servers a.dnspod.com, b.dnspod.com, and c.dnspod.com, indicating the use of the DNSPod service. Threat intelligence records classify the site as a generic phishing operation and assign it a high risk rating.
As of the report date, July 31, 2026, the domain appears on a single security blocklist and is actively blocked by the PhishDestroy mitigation service. VirusTotal analysis shows that three of ninety‑one scanning engines have flagged the domain, providing additional corroboration of malicious intent. No further public data such as SSL certificate details, HTTP response codes, or page title have been disclosed, leaving the content and exact phishing vector unverified.
The limited detection footprint—three vendor detections and a solitary blocklist entry—suggests that the campaign may be in an early deployment phase or that broader detection coverage is pending. Defenders should add rarelocker.com to domain blocklists, monitor outbound connections to its hosting IP, and enforce URL filtering policies that reference the known name server set. Continuous re‑evaluation is recommended, as additional security vendors may subsequently flag the domain and further blocklist entries could emerge, expanding the observable threat surface.