flr[.]report
This domain is flagged as a credential harvesting phishing site with an elevated risk level. Analysis indicates it was designed to mimic legitimate login portals, likely targeting users through deceptive email or SMS campaigns to capture sensitive authentication details. The infrastructure and timing suggest a short-lived, high-impact operation typical of modern phishing threats. Infrastructure analysis reveals the domain flr.report was registered on May 16, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to the IP address 172.67.69.159, a Cloudflare-hosted endpoint, and presents a Let's Encrypt SSL certificate. The page title 'Just a moment...' is consistent with Cloudflare's interstitial challenge page, though this may have been used to mask malicious activity. Security vendors on VirusTotal flagged the domain at a 1/95 detection rate, and it appears on one security blocklist. Gridinsoft assigned a trust score of 0/100, further confirming its malicious nature. The domain has since been taken offline, but residual risks remain for users who may have interacted with it prior to deactivation. Mitigation steps should focus on containment and user awareness. Organizations should block the domain flr.report and its associated IP 172.67.69.159 at the firewall or DNS level to prevent accidental access. Users who may have entered credentials should be instructed to reset passwords immediately and enable multi-factor authentication on all accounts. Security teams should review logs for connections to the domain or IP and monitor for signs of compromised credentials. Given the domain's recent registration and rapid takedown, similar threats may emerge under different names, necessitating continuous monitoring of newly registered domains with similar patterns.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-22 02:44:43 UTC
Technologies · 1 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of flr.report · checked Jun 26, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive