Analysis on asd123o.com, first observed on June 12 2026, indicates that the domain is being used for a generic phishing campaign. The domain was registered through NameMart Pte. Ltd. and is delegated to Cloudflare name servers deb.ns.cloudflare.com and elmo.ns.cloudflare.com. DNS resolution points to IP address 104.21.40.10, which belongs to Cloudflare's network, suggesting the infrastructure is leveraging a reputable CDN to hide the true origin of the payload. The domain has been submitted to VirusTotal where 91 antivirus and scanning engines evaluated the associated resources; none reported a detection at the time of analysis.
While the lack of detections does not imply benign intent, it indicates that the payload, if any, may be employing evasion techniques or that the content has not yet been captured by the scanners. The domain is currently listed on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that at least one threat‑intelligence source has identified malicious activity tied to the host. No public page title, SSL certificate details, or brand targeting information have been released, leaving those aspects of the campaign unverified. The short age of the domain—less than two months old—combined with the rapid appearance on a blocklist is consistent with opportunistic phishing operations that register fresh domains for short‑lived campaigns.
Defenders should continue to monitor DNS queries for 104.21.40.10 and consider adding asd123o.com to local deny lists. Network traffic to the Cloudflare edge should be inspected for anomalous HTTP requests, and any email or credential‑harvesting attempts referencing the domain should be quarantined. Because the underlying server is hidden behind Cloudflare, traditional sink‑hole techniques may be limited; collaboration with the hosting provider or Cloudflare abuse channels may be required for takedown.