blackworld.digital Generic Phishing Alert
Analysis of the domain blackworld.digital, created on July 24, 2026, indicates that it is being used for a generic phishing operation.
Analysis of the domain blackworld.digital, created on July 24, 2026, indicates that it is being used for a generic phishing operation. The domain is registered through Fewmoretaps OU d/b/a Trustname.com and is hosted on the IP address 188.114.96.3, served by Cloudflare nameservers owen.ns.cloudflare.com and tina.ns.cloudflare.com. VirusTotal reports that the domain has been scanned by 91 independent vendors, none of which currently flag it as malicious; this lack of detections does not constitute a safety guarantee.
The domain is listed on one external security blocklist and has been actively blocked by the PhishDestroy sinkhole, confirming that threat‑intelligence communities have identified it as hostile. Its current status remains active, suggesting that the phishing infrastructure is still operational. No additional evidence such as page titles, SSL certificates, HTTP response codes, or Safe Browsing identifiers is available at this time, leaving the precise luring technique and target brand undefined.
Defenders should add the domain to local URL filtering rules, monitor DNS queries for 188.114.96.3 and the associated Cloudflare nameservers, and consider sharing the indicator set with upstream blocklists to increase coverage. Continued observation of traffic to the domain and periodic rescans on VirusTotal are recommended to detect any future shifts in vendor detection status.