Analysis of foodjolt.com shows that the domain was registered through Namecheap Inc on 10 October 2023 and currently resolves to the IP address 188.114.96.3, which belongs to Cloudflare’s network. The authoritative nameservers listed are molly.ns.cloudflare.com and ryan.ns.cloudflare.com, indicating the use of Cloudflare’s DNS and edge services. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that it is being used for malicious purposes. VirusTotal has recorded 91 vendor submissions for the domain, and none of the scanners returned a detection at the time of analysis; this absence of detections does not imply safety and should be interpreted as a lack of current signatures.
No additional telemetry such as page title, SSL certificate details, HTTP response codes, or Safe Browsing verdicts is publicly available, so the exact content and lure technique remains unverified. The limited evidence points to a generic phishing operation, but the specific target or credential‑stealing vector has not been disclosed. Defenders should proactively block foodjolt.com at perimeter firewalls and DNS resolvers, add the domain to internal threat‑intel feeds, and monitor for any related subdomains or newly observed IP associations.
Continuous re‑scanning on multi‑vendor platforms is recommended to capture any future payloads or changes in behavior. Organizations that rely on email or web gateway filtering should ensure that their rules reference the observed blocklist entries and that alerts are generated for any outbound connections to the IP address 188.114.96.3. Given the active status and recent registration date, the domain should be treated as high‑risk until further forensic analysis clarifies its operational scope.