Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 9. Public blocklists reporting a match: 4. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

allocations-gensyn[.]network

“$AI Sale Allocations”

Threat verdict Critical 82/100 evidence score
Availability Server error The latest stored response was inconclusive
VirusTotal detections: 9/93 Stored blocklist matches: 4 Brand impersonation: Across
Dec 28, 2025 Across CDN

Evidence Summary

CRITICAL
Evidence score
82/100

The domain allocations-gensyn.network was registered on December 26, 2025 through NiceNIC International Group Co., Limited and is hosted on Cloudflare infrastructure (AS13335) with the IP address 172.67.207.57 located in the United States. The site is currently offline, but historical evidence indicates it was used for a wallet/seed phishing campaign targeting the brand "across" and presenting a page titled "$AI Sale Allocations". No TLS certificate was observed, resulting in an unencrypted HTTP endpoint. Reputation checks show a Gridinsoft trust score of 0 out of 100, and the domain is listed on five independent security blocklists, specifically PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura.

VirusTotal analysis recorded nine positive detections out of ninety‑three scanning engines, confirming malicious intent. The domain resolves via the Cloudflare nameservers cloe.ns.cloudflare.com and mitch.ns.cloudflare.com, a common pattern for fast‑flux or abuse of reputable CDN services. While the exact content of the phishing page has not been captured, the combination of brand impersonation, wallet/seed credential harvesting, and the observed infrastructure strongly suggests a coordinated credential‑stealing operation.

Uncertainty remains regarding the current activity level and whether additional sub‑domains are being leveraged for the same campaign. Defenders should block the domain and its associated IP at perimeter defenses, monitor for any DNS queries to the listed Cloudflare nameservers, and add the domain to internal threat‑intel feeds. Incident responders should also treat any credentials or seed phrases reported from interactions with this site as compromised and advise affected users to rotate their wallets immediately.

VirusTotal
VirusTotal
9 det.
Age
8 mo
Observed status
Server error HTTP 502
PhishDestroy
DestroyList
Listed

Data Coverage

VirusTotal 9 / 93 URLQuery report stored — detailed verdict pending PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict Analysis completed DNS blocks not checked TLS no certificate data WHOIS 8 mo old Screenshot 2 captures · 2 sources Redirect chain not probed
Network Security IntelligenceRegistrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Threat Response Pipeline

Discovery
Checks
Reports
Availability
12/14

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 11, 2026

6 monitored external feeds No match

Stored outcome evidence

Outcome & takedown attribution

Outcome
held
Availability
unreachable
Cause
registrar_client_hold
Actor
NICENIC INTERNATIONAL GROUP CO., LIMITED
Mechanism
client_hold
Confidence
95%
First observation
Latest observation

Estimated unavailability

Time to unavailability: 0 h

Evidence SHA-256 261a3bb9cc16

Detection timeline

  1. Cloudflare Radar

    Cloudflare Radar scan stored · Open scan

  2. Availability

    First stored value: DNS inactive

    f93a11f87e4d
  3. Availability

    DNS inactive → Unknown

    4e219cff538a
  4. Availability

    Unknown → Inactive

    208556e72888
  5. Availability

    Inactive → DNS inactive

    1c52190a0bf5
  6. Availability

    DNS inactive → Held

    dd632912fb56
  7. Availability

    Held → DNS inactive

    f52d526b76a1
  8. Availability

    DNS inactive → Unknown

    b593afb0cf1c
  9. Availability

    Unknown → Held

    2ecd9ba0677b
  10. Availability

    Held → Unknown

    e4b5a8097d68
Show all (11)
  1. Availability

    Unknown → DNS inactive

    6dfe9145995c
  2. Availability

    DNS inactive → Held

    d195a19e3d0f
  3. Availability

    Held → DNS inactive

    641ed81dc4d5
  4. Availability

    DNS inactive → Unknown

    35d9e60d14a7
  5. Availability

    Unknown → Held

    8e1b28315653
  6. Availability

    Held → Unknown

    0b8b9b4b5b8f
  7. Availability

    Unknown → DNS inactive

    d0b7046e8c2f
  8. Availability

    DNS inactive → Held

    021fa176e78c
  9. Availability

    Held → DNS inactive

    ca9ed662b468
  10. Availability

    DNS inactive → Unknown

    3a5377ae30a6
  11. Availability

    Unknown → Held

    261a3bb9cc16

Community reports

Reported by 1 community member, first seen Dec 28, 2025

Stored reports
1
Unique reported URLs
1
Accepted1

Stored Capture

Page Title
$AI Sale Allocations
Impersonates
Across Discord Ethereum Foundation Minecraft

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN cloudflare · AS13335 CLOUDFLARENET, US
IP Context Cloudflare shared edge origin IP hidden Edge-IP reputation is not attributed to this domain.
IP Address 172.67.207.57 CDN
GeoUS San Francisco, US
NetworkAS13335 · Cloudflare, Inc.
The origin IP is hidden behind a CDN proxy. Reverse-IP results for the edge address contain unrelated tenants; finding the origin requires passive DNS or certificate-transparency data.
RegistrationCreated Dec 26, 2025 (228d) Expires Dec 26, 2026
HTTP Status502 Error
Elapsed Since First Report 137 days
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Server error.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, TLS names and timestamps
First DetectedDec 28, 2025
DOM Analysisanalyzed Apr 23, 2026DOM analysis score 15/1005 brand signals
Submitted URLhttp://allocations-gensyn.network/
Nameserverscloe.ns.cloudflare.commitch.ns.cloudflare.com
TLS observationscanned Mar 14, 2026
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

9 / 93 security vendors flagged this domain
View on VT
Last analyzed
ChainPatrol
alphaMountain.ai
CRDF
CyRadar
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
Seclookup
SOCRadar

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/allocations-gensyn.network"
  title="PhishDestroy threat report for allocations-gensyn.network"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.