Analysis of promo-settings.com indicates that the domain is actively being used for a generic phishing campaign. The domain was registered on July 28, 2026 through Fewmoretaps OU d/b/a Trustname.com and resolves to the IP address 188.114.96.3. Its authoritative nameservers are algin.ns.cloudflare.com and marjory.ns.cloudflare.com, confirming that the hosting infrastructure is provided by Cloudflare.
The domain appears on three independent security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, suggesting that multiple threat intelligence sources have observed malicious activity associated with this host. VirusTotal records show that the domain has been scanned by 91 antivirus and URL‑reputation vendors; none of the scanned samples returned a detection, a result that the report explicitly notes does not constitute evidence of safety. The current operational status is listed as active, and no public information on HTTP response codes, SSL certificate details, or page title has been released, leaving the exact content of the site unverified.
Defenders should treat the domain as high‑risk: network perimeter devices, DNS filtering solutions, and endpoint security products should enforce blocks against promo-settings.com, and any inbound or outbound traffic to the associated IP address 188.114.96.3 should be monitored for anomalous patterns. Continuous re‑evaluation is recommended, as the lack of detection on VirusTotal may change if the threat actors modify payloads or hosting. Organizations should also consider adding the domain to internal blocklists and sharing indicators of compromise with peer security communities to improve collective detection capability.