Analysis of flintanchorlabs.com indicates that the domain was registered on July 03, 2026 through Ultahost, Inc. and is currently active. The authoritative nameservers are fatima.ns.cloudflare.com and memphis.ns.cloudflare.com, pointing to the Cloudflare network. DNS resolution returns the address 104.21.17.100, which belongs to Cloudflare’s edge infrastructure. The domain appears on one public security blocklist and has been explicitly blocked by the PhishDestroy service, confirming its use in malicious campaigns.
VirusTotal scans show that 2 of 91 security vendors have flagged the domain, providing independent confirmation of its malicious reputation. No additional telemetry such as page title, SSL certificate details, HTTP response codes, or brand targeting has been released, leaving the exact phishing lure undefined. The lack of publicly available content means that defenders cannot assess the specific victim‑facing page, but the presence on a blocklist and multiple vendor detections is sufficient to classify the domain as high‑risk for generic phishing. Given the recent creation date, the Cloudflare hosting, and the active status, threat actors may be leveraging the platform’s anonymity and rapid provisioning to host phishing pages.
Defenders should add flintanchorlabs.com to web filtering and DNS block policies, monitor outbound connections to the resolved IP 104.21.17.100, and consider sharing the indicator with internal threat‑intel feeds. Continuous re‑scanning with VirusTotal or similar services is recommended to capture any future changes in vendor verdicts. Because the domain is newly created, any legitimate traffic to this host is unlikely; therefore, any observed access should be treated as suspicious and investigated further.