Analysis of the domain jojobet-mobil-online.icu shows an active generic phishing infrastructure as of the report date, July 31, 2026. The domain was registered only five days earlier, on July 26, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, and is hosted on the IP address 188.114.96.3. DNS resolution points to Cloudflare nameservers chris.ns.cloudflare.com and gail.ns.cloudflare.com, indicating the use of a reputable CDN service to obscure the true origin of the traffic.
The domain appears on one public security blocklist and is actively blocked by the PhishDestroy mitigation service, confirming that at least one downstream security platform has identified it as malicious. VirusTotal scans have resulted in four of ninety‑one security vendors flagging the domain, providing additional independent corroboration of its malicious nature. No further detail on the specific phishing kit, targeted brand, or page content is available at this time.
Given the recent creation date, the use of a well‑known CDN, and the early detection by multiple vendors, defenders should prioritize immediate containment. Recommended actions include adding the domain to local blocklists, configuring DNS sinkholing for 188.114.96.3, and monitoring for any related subdomains or new registrations that resolve to the same IP address. Continuous re‑scanning on VirusTotal and inclusion in threat‑intel sharing platforms will help track any evolution of the campaign.