Analysis indicates that rainbet.mx is an active phishing domain targeting users of online betting platforms. The domain was registered on February 26, 2026, through Dynadot Inc, a registrar frequently associated with fraudulent activity. Infrastructure analysis reveals it resolves to the IP address 188.114.97.3, which is part of Cloudflare's network, a common tactic to obscure hosting origins and evade IP-based blocking. The domain uses Cloudflare nameservers (oswald.ns.cloudflare.com and rachel.ns.cloudflare.com), further complicating attribution and takedown efforts.
As of July 28, 2026, rainbet.mx appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, which classify it as a high-risk phishing threat. VirusTotal reports that 3 out of 91 security vendors flag the domain, though the specific detection rules or payloads are not disclosed in available intelligence. The domain remains active, with no evidence of suspension or deactivation by the registrar or hosting provider. The exact content of rainbet.mx has not been fully analyzed, so the precise phishing mechanics—such as credential harvesting, payment fraud, or malware distribution—remain uncertain.
However, the domain name and detection context strongly suggest an attempt to impersonate a legitimate betting service to deceive users into submitting sensitive information. Defenders should treat this domain as malicious and implement blocking at the DNS, proxy, or endpoint level. Organizations are advised to monitor for connections to 188.114.97.3 and review logs for any user interactions with rainbet.mx, particularly in regions where online betting is prevalent. Further investigation into the domain's hosting history and associated infrastructure may reveal additional linked threats.