Analysis indicates that launch-firelight.xyz was registered on July 31 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolving to the IP address 188.114.97.3. The domain is hosted on Cloudflare infrastructure, as evidenced by the authoritative nameservers elle.ns.cloudflare.com and ruben.ns.cloudflare.com. Early detection activity shows the domain was added to a single security blocklist and has been flagged by the PhishDestroy sinkhole, confirming its malicious intent.
VirusTotal reports three of ninety‑one scanned scanners label the domain as malicious, reinforcing the suspicion of phishing usage. No additional public threat‑intel sources such as OTX or Google Safe Browsing have published entries for this domain at the time of writing, and no SSL certificate details or HTTP response codes have been disclosed. The limited visibility suggests that the campaign is newly deployed, with the short lifespan between registration and first detection indicating a rapid‑turnover approach typical of generic phishing operations.
Defenders should block any outbound connections to 188.114.97.3, add launch-firelight.xyz to local deny lists, and monitor for any traffic anomalies targeting the domain. Continuous re‑query of the domain against updated blocklists and sandbox environments is advised to capture any evolving payloads or credential‑harvesting pages that may appear.