This report analyzes the domain nam-hnw-form.com, which is currently flagged as an active generic phishing threat. The domain was created on July 27, 2026, and remains operational as of the report date of July 31, 2026. It resolves to IP address 172.67.208.246 and uses Cloudflare nameservers (kinsley.ns.cloudflare.com and mitchell.ns.cloudflare.com), indicating the domain is behind a content delivery network that can obscure the origin server's location and hosting provider. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar commonly associated with low-cost, rapid registrations that may be favored for malicious campaigns.
VirusTotal has scanned this domain with 91 vendors; as of this report, none currently flag it as malicious. This absence of detections is not proof of safety, as phishing domains often evade automated scanners early in their lifecycle. The domain appears on one security blocklist and is blocked by PhishDestroy, a specific anti-phishing service that has identified it as a threat. No Safe Browsing, OTX, SSL certificate, HTTP status, or trust score data is available in the current intelligence.
The exact content hosted on the domain has not yet been analyzed, so no specific brand, page title, or phishing kit can be confirmed; the classification as generic phishing is based on the blocklist and anti-phishing service flags. Defenders should treat this domain as a potential credential-harvesting or data-collection site, monitor internal logs for any attempts to access it, and consider blocking it at the network level. Given its recent creation and active status, the domain may evolve or be replaced with new infrastructure; ongoing monitoring is advised. Organizations should also review registrar and DNS details to identify related domains registered in the same batch or using similar infrastructure patterns.