Analysis indicates that the domain luonvuituoi.live was registered on July 24, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED. As of July 28, 2026, the domain remains active and resolves to the IP address 172.67.211.31, which is part of Cloudflare’s infrastructure, as evidenced by the nameservers anahi.ns.cloudflare.com and huxley.ns.cloudflare.com. The domain appears on one security blocklist and is flagged by two of ninety-one security vendors on VirusTotal, classifying it as a generic phishing threat. No specific brand impersonation, phishing kit, or targeted sector has been confirmed in available data, though the domain’s structure and detection patterns suggest it is designed to mimic login portals or credential-harvesting pages.
Infrastructure analysis reveals the use of Cloudflare services, which may obscure the true hosting origin and complicate takedown efforts. The registrar, NICENIC INTERNATIONAL GROUP CO., LIMITED, has been associated with other high-risk domains in prior campaigns, though no direct attribution to a known threat actor or group is currently established. The domain’s creation date aligns with recent phishing activity trends, where newly registered domains are rapidly deployed to evade detection. Defenders are advised to block the domain at the DNS or network level, particularly in environments where credential theft poses a critical risk.
Monitoring for connections to 172.67.211.31 and associated subdomains is recommended. Given the domain’s active status and minimal detection coverage, further investigation into its content and payload delivery mechanisms is warranted. Organizations should treat this domain as high-risk until additional telemetry confirms its removal or neutralization.