The domain 3658992.cc was registered on July 18, 2026 via Dynadot Inc and is currently resolved to the IP address 40.81.18.27. DNS resolution is provided by the Cloudflare nameservers dalary.ns.cloudflare.com and jacob.ns.cloudflare.com, indicating use of Cloudflare’s DNS infrastructure. Threat intelligence sources list the domain as active and classify it as a generic phishing operation.
VirusTotal scans show that 11 out of 91 security vendors have flagged the domain, providing independent confirmation of malicious intent. The domain appears on two public blocklists, including PhishDestroy and OpenPhish, both of which have taken it down in their respective filtering services. No public information is available regarding the site’s SSL certificate, HTTP response codes, page title, or any associated landing page content, leaving the exact phishing vector unspecified.
The limited data suggests a short‑lived infrastructure that leverages reputable DNS services to hide its origins while targeting users with phishing payloads. Defenders should add the IP address 40.81.18.27 and the domain 3658992.cc to perimeter blocks, enforce DNS filtering against the listed blocklists, and monitor outbound traffic for connections to the Cloudflare nameservers associated with this domain. Continuous re‑scanning on multi‑vendor platforms is recommended to capture any evolution in detection rates, and any observed malicious payloads should be submitted to threat‑intel sharing communities for broader awareness.