# PhishDestroy threat dossier — flarenetworks-gover.xyz ================================================================ Fetched: 2026-06-25 00:51:30 UTC Canonical: https://phishdestroy.io/domain/flarenetworks-gover.xyz/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 64/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: G-Data, LevelBlue, Netcraft, Sophos URLQuery: 3 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: keaton.ns.cloudflare.com, oaklyn.ns.cloudflare.com Registered: 2026-06-24 Expires: 2027-06-24 HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-24 18:49:06 UTC (by PhishDestroy tracker) First reported: 2026-06-24 16:59:47 UTC (abuse notice filed) Last verified: 2026-06-25 00:20:44 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019efa88-5297-717a-b4f2-382d52d82b6e/ URLQuery: https://urlquery.net/report/48e9338b-8a5c-419b-a764-7955cceaa223 Wayback Machine: https://web.archive.org/web/*/flarenetworks-gover.xyz crt.sh CT logs: https://crt.sh/?q=%25.flarenetworks-gover.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=flarenetworks-gover.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/flarenetworks-gover.xyz URLhaus: https://urlhaus.abuse.ch/host/flarenetworks-gover.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-24 20:25:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain flarenetworks-gover.xyz has been identified as a generic phishing site, currently active and posing a significant threat to users. This type of phishing attack typically involves tricking victims into revealing sensitive information such as login credentials or financial data. Furthermore, the fact that it is impersonating a legitimate brand, albeit not explicitly stated, adds to the complexity of the threat. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, which may indicate a level of sophistication in the phishing campaign. In analyzing the domain's infrastructure, it becomes clear that flarenetworks-gover.xyz has been flagged by 4 out of 95 VirusTotal security vendors, indicating a potential threat to users. Additionally, the domain appears on 3 security blocklists, which further solidifies its status as a malicious site. The domain was registered on June 24, 2026, and resolves to the IP address 188.114.97.3, which may be hosted by a provider that is unaware of the malicious activity. The registrar, NICENIC INTERNATIONAL GROUP CO., LIMITED, has a responsibility to ensure that the domains registered through them do not engage in malicious activities. The threat mechanism behind flarenetworks-gover.xyz involves tricking users into divulging sensitive information, which can then be used for malicious purposes such as identity theft or financial fraud. Typical victim scenarios include receiving an email or message with a link to the phishing site, where the user is prompted to enter their login credentials or other sensitive information. The attackers may use social engineering tactics to make the site appear legitimate, increasing the likelihood of a successful phishing attempt. In some cases, the phishing site may also be designed to drain cryptocurrency wallets or install malware on the victim's device. The current status of flarenetworks-gover.xyz indicates that it is still active, despite being flagged by security vendors and appearing on blocklists. Takedown efforts may be underway, but the community response has been limited, and the risks associated with the domain remain high. Users who have already interacted with the site should be cautious and monitor their accounts for any suspicious activity. Furthermore, security researchers and law enforcement agencies should continue to monitor the domain and work towards taking it down to prevent further damage. To stay safe, users should avoid interacting with flarenetworks-gover.xyz and be cautious when receiving emails or messages with links to unfamiliar sites. It is essential to verify the authenticity of a site before entering sensitive information, and users should always prioritize security when browsing the internet. For example, users can check the site's URL for any spelling mistakes or unusual characters, and look for a padlock icon in the address bar to ensure the site is secure. By taking these precautions, users can significantly reduce the risk of falling victim to phishing attacks and protect their sensitive information. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260624-737B61 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/flarenetworks-gover.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=flarenetworks-gover.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 169,652 domains (15,774 alive under monitoring, 153,512 confirmed takedowns/dead). Site: https://phishdestroy.io