allocations-gensyn[.]network
“$AI Sale Allocations”
Evidence Summary
The domain allocations-gensyn.network was registered on December 26, 2025 through NiceNIC International Group Co., Limited and is hosted on Cloudflare infrastructure (AS13335) with the IP address 172.67.207.57 located in the United States. The site is currently offline, but historical evidence indicates it was used for a wallet/seed phishing campaign targeting the brand "across" and presenting a page titled "$AI Sale Allocations". No TLS certificate was observed, resulting in an unencrypted HTTP endpoint. Reputation checks show a Gridinsoft trust score of 0 out of 100, and the domain is listed on five independent security blocklists, specifically PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura.
VirusTotal analysis recorded nine positive detections out of ninety‑three scanning engines, confirming malicious intent. The domain resolves via the Cloudflare nameservers cloe.ns.cloudflare.com and mitch.ns.cloudflare.com, a common pattern for fast‑flux or abuse of reputable CDN services. While the exact content of the phishing page has not been captured, the combination of brand impersonation, wallet/seed credential harvesting, and the observed infrastructure strongly suggests a coordinated credential‑stealing operation.
Uncertainty remains regarding the current activity level and whether additional sub‑domains are being leveraged for the same campaign. Defenders should block the domain and its associated IP at perimeter defenses, monitor for any DNS queries to the listed Cloudflare nameservers, and add the domain to internal threat‑intel feeds. Incident responders should also treat any credentials or seed phrases reported from interactions with this site as compromised and advise affected users to rotate their wallets immediately.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
6 monitored external feeds No match
Stored outcome evidence
Outcome & takedown attribution
- Outcome
held- Availability
unreachable- Cause
registrar_client_hold- Actor
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mechanism
client_hold- Confidence
- 95%
- First observation
- Latest observation
Estimated unavailability
Time to unavailability: 0 hEvidence SHA-256 261a3bb9cc16
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
-
Availability
First stored value: DNS inactive
f93a11f87e4d -
Availability
DNS inactive → Unknown
4e219cff538a -
Availability
Unknown → Inactive
208556e72888 -
Availability
Inactive → DNS inactive
1c52190a0bf5 -
Availability
DNS inactive → Held
dd632912fb56 -
Availability
Held → DNS inactive
f52d526b76a1 -
Availability
DNS inactive → Unknown
b593afb0cf1c -
Availability
Unknown → Held
2ecd9ba0677b -
Availability
Held → Unknown
e4b5a8097d68
Show all (11)
-
Availability
Unknown → DNS inactive
6dfe9145995c -
Availability
DNS inactive → Held
d195a19e3d0f -
Availability
Held → DNS inactive
641ed81dc4d5 -
Availability
DNS inactive → Unknown
35d9e60d14a7 -
Availability
Unknown → Held
8e1b28315653 -
Availability
Held → Unknown
0b8b9b4b5b8f -
Availability
Unknown → DNS inactive
d0b7046e8c2f -
Availability
DNS inactive → Held
021fa176e78c -
Availability
Held → DNS inactive
ca9ed662b468 -
Availability
DNS inactive → Unknown
3a5377ae30a6 -
Availability
Unknown → Held
261a3bb9cc16
Community reports
Reported by 1 community member, first seen Dec 28, 2025
- Stored reports
- 1
- Unique reported URLs
- 1
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive