The domain jointrwcoin.com is currently flagged as a high-risk generic phishing threat. Multiple technical signals indicate ongoing malicious activity. The domain was registered through Ultahost, Inc. on July 6, 2026, and remains active as of July 30, 2026. It utilizes a set of nameservers hosted by ultahost.com (ns1 through ns4), and resolves to the IP address 72.61.65.150. This domain is actively listed on at least one security blocklist and has been specifically blocked by the PhishDestroy service, reinforcing the assessment of phishing activity associated with it.
Additional evidence from VirusTotal shows 4 out of 91 security vendors currently flag this domain for malicious activity, providing further indication of the threat it poses. However, the specific content or exact phishing method used by jointrwcoin.com has not been directly analyzed; there is no available page title or reference to a targeted brand or a particular scam type in the current intelligence.
Given the active status of the domain, its recent creation, hosting infrastructure, and blocklist detection, defenders should move quickly to block access and monitor for related indicators of compromise within their networks. While the exact tactics or victim targeting are not yet confirmed, the cumulative technical findings are sufficient to recommend immediate preventative action. Any further analysis should focus on obtaining the web content and monitoring any updates to security vendor detections or blocklist coverage.