Analysis of the domain blackops-access.sbs indicates that it is currently active and associated with a generic phishing campaign. The domain was registered on July 25, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IP address 188.114.97.3, which is hosted on Cloudflare infrastructure as evidenced by the authoritative name servers adel.ns.cloudflare.com and javon.ns.cloudflare.com. VirusTotal has recorded detections from two of ninety‑one security vendors, confirming that at least a small subset of scanning engines recognize malicious behavior.
The domain also appears on a single security blocklist and is explicitly listed by PhishDestroy as a blocked resource. No additional intelligence such as page titles, SSL certificate details, HTTP response codes, or brand targeting is available at this time. The limited detection count and singular blocklist entry suggest that the malicious infrastructure is newly deployed, consistent with the recent registration date.
Defenders should treat the domain as high‑risk, enforce outbound filtering to block connections to the resolved IP, and add the fully qualified domain name to internal blocklists and DNS sinkhole configurations. Continuous monitoring of DNS queries for the domain and its associated Cloudflare name servers is advised, as any change in resolution could indicate a shift in hosting or expansion of the phishing infrastructure. Organizations should also consider sharing any future observations with threat‑intelligence platforms to improve community detection coverage.