onlinedoctorconsult.org was registered on July 21, 2026 through the registrar Fewmoretaps OU d/b/a Trustname.com. The domain is delegated to the Cloudflare name servers cruz.ns.cloudflare.com and kyrie.ns.cloudflare.com, which place the domain within Cloudflare’s globally distributed edge network. DNS resolution points to the IP address 188.114.96.3, an address owned by Cloudflare and commonly used by hosted malicious services to obscure the underlying server location. The domain is listed on one public security blocklist and has been explicitly tagged by the PhishDestroy intelligence feed as an active generic phishing infrastructure.
VirusTotal reports indicate that the domain has been examined by 91 distinct antivirus and URL‑reputation engines; none of the engines raised a detection at the time of analysis. This lack of detections should not be interpreted as a confirmation of safety, as phishing sites often evade static signatures and may only be identified by behavioural analysis. Current public data does not include a Google Safe Browsing verdict, Open Threat Exchange (OTX) entries, SSL/TLS certificate details, or HTTP status codes for the site, and the page title has not been harvested. Consequently, the precise content served by the domain remains unknown, although the choice of domain name suggests a medical‑related social engineering lure.
Given the active status, defenders are advised to proactively block traffic to 188.114.96.3 at the network perimeter and to add onlinedoctorconsult.org to web‑proxy, DNS, and email filtering blocklists. Continuous monitoring of the domain through automated re‑scans on VirusTotal and similar sandbox platforms is recommended to capture any later deployment of malicious payloads. Analysts should also track other domains registered by Fewmoretaps OU or using the same Cloudflare name servers, as historical patterns indicate that such infrastructure is often reused across coordinated phishing campaigns.