Analysis of the domain pub-feace8375b50491084e257e8c6d61cc3.r2.dev indicates it is under investigation for phishing activity as of July 29, 2026. The domain is currently active and appears on at least one security blocklist, specifically PhishDestroy. Infrastructure analysis reveals the domain resolves to the IP address 104.18.50.34, which is associated with Cloudflare's content delivery network. Notably, the domain lacks configured nameservers, a potential indicator of misconfigured or hastily deployed malicious infrastructure.
The registrar is Cloudflare, Inc., a common choice for both legitimate and fraudulent domains due to its privacy and accessibility features. While the domain has been scanned by 91 security vendors on VirusTotal, none have flagged it as malicious at this time. However, the absence of detections does not confirm safety, as phishing domains often evade initial detection through obfuscation or delayed malicious payloads.
The exact content and target of the phishing site remain unconfirmed, as no specific brand, page title, or phishing kit details are available in the current intelligence. Defenders should treat this domain as high-risk until further analysis confirms its intent. Organizations are advised to block access to this domain at the network level, monitor for connections to the associated IP, and report any observed malicious activity to threat intelligence platforms for broader awareness.