The domain firelight-get.xyz was registered on July 31, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolving to the IP address 188.114.96.3. Its authoritative name servers are elaine.ns.cloudflare.com and hasslo.ns.cloudflare.com, indicating the use of Cloudflare's DNS and CDN services. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy platform, yet it remains active as of the report date, August 01, 2026.
VirusTotal analysis shows that three out of ninety‑one scanned security vendors flagged the domain, providing modest but notable detection confidence. No additional contextual data such as page title, SSL certificate details, or HTTP response codes are available, leaving the specific phishing payload and target brand unconfirmed. The rapid creation-to‑activity timeline suggests a short‑lived campaign, typical of opportunistic phishing operators who favor disposable domains to evade early takedown.
The use of Cloudflare may obscure the true hosting environment, but the public IP 188.114.96.3 can be added to network‑level blocklists to prevent outbound connections to the service. Defenders should ingest the domain into existing URL filtering and web proxy rules, monitor DNS queries for the associated Cloudflare name servers, and consider raising the indicator in threat‑intel feeds to ensure broader community awareness. Continuous re‑evaluation is advised, as further scanning by additional vendors or the emergence of page‑level evidence could elevate the threat rating.