On 29 July 2026 the domain wwv-jojobet-yeni.vip was observed as an active generic phishing infrastructure. The domain resolves to the IPv4 address 188.114.96.3 and is served through Cloudflare name servers armfazh.ns.cloudflare.com and stephane.ns.cloudflare.com. The hosting provider is not directly disclosed, but the IP belongs to the Cloudflare network, suggesting the attacker is leveraging a CDN for anonymity and rapid content delivery. The domain has been added to the PhishDestroy blocklist and appears on one additional security blocklist, indicating that at least two independent threat‑intelligence feeds have flagged it.
VirusTotal has processed the domain with 91 antivirus and URL‑reputation engines; none of the engines raised a detection, which reflects the current lack of signature‑based indicators rather than an assurance of benign behavior. No public Safe Browsing, OTX, or SSL certificate details are available in the supplied intelligence, and the page title or any brand targeting information has not been disclosed. Consequently, the precise content of the phishing page remains unknown, and the targeted brand or credential‑capture technique cannot be confirmed.
Defenders should treat the domain as malicious based on its blocklist presence and infrastructure characteristics. Recommended mitigations include adding wwv-jojobet-yeni.vip to URL filtering rules, blocking outbound connections to 188.114.96.3, and monitoring DNS queries for the associated Cloudflare name servers. Continuous re‑evaluation is advised, as further analysis may reveal additional indicators such as page content, SSL fingerprints, or victim reports.