Analysis of rainbets.vip, flagged as a generic phishing site with a high risk rating, shows that the domain remains active as of the report date, July 28, 2026. The domain is delegated to OpenProvider infrastructure, using the authoritative name servers ns1.openprovider.nl, ns2.openprovider.be, and ns3.openprovider.eu. DNS resolution points to the IPv4 address 183.81.169.24, which is the sole host observed for this domain.
VirusTotal has recorded five detections out of ninety‑one scanned security vendors, indicating that a minority of scanners have identified malicious characteristics. Independent blocklist providers have taken action: PhishDestroy, MetaMask, and SEAL list the domain as blocked, and it appears on three additional security blocklists, reinforcing the consensus that the domain is being used for malicious purposes. No publicly available SSL/TLS certificate details, HTTP status codes, or page title information have been disclosed, leaving the exact content of the site unverified.
The lack of such telemetry limits the ability to confirm the specific phishing payload or target brand, but the existing indicators—multiple blocklist entries, partial VirusTotal detections, and dedicated phishing‑focused blocking by MetaMask—provide sufficient evidence for defensive measures. Organizations should add rainbets.vip to domain‑based deny lists, block outbound connections to 183.81.169.24, and monitor DNS query logs for any resolution attempts. Continuous re‑evaluation is advised in case additional intelligence, such as HTTP response data or SSL certificate analysis, becomes available.