The domain open-osint.group was registered on July 28, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently active. The DNS resolution points to the IPv4 address 45.83.179.201, served by authoritative nameservers ns1.example.com and ns2.example.com. The domain has been observed on a single security blocklist and is actively blocked by the PhishDestroy feed, indicating that at least one external threat‑intelligence source has classified it as malicious. VirusTotal records show that the domain was scanned by 91 antivirus and URL‑reputation vendors; none of those scanners raised a detection at the time of analysis.
While the absence of detections does not constitute evidence of benign intent, it does demonstrate that the domain has not yet triggered automated signatures in the tested engines. No public Safe Browsing, Open Threat Exchange, SSL certificate, HTTP response code, or trust‑score data were available for the domain at the time of assessment, and the page title has not been captured. Consequently, the current evidence base is limited to registration details, DNS configuration, blocklist presence, and the VirusTotal scan count.
Given the recent creation date, the active status, and the blocklist inclusion, defenders should treat open-osint.group as a high‑confidence phishing indicator. Recommended actions include adding the domain to internal deny lists, monitoring DNS queries for the associated IP address, and employing outbound web‑filter rules to block HTTP(S) traffic to the host. Continuous re‑evaluation is advised, as additional telemetry such as SSL analysis, HTTP payload inspection, or community threat‑intel feeds may emerge and refine the risk posture.