# PhishDestroy threat dossier — lucenclouds.org ================================================================ Fetched: 2026-07-27 05:56:23 UTC Canonical: https://phishdestroy.io/domain/lucenclouds.org/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 69/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, Lionic, Netcraft, Sophos AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.4.122 Registrar: Sav.com, LLC Nameservers: arya.ns.cloudflare.com, damien.ns.cloudflare.com Registered: 2025-06-28 Expires: 2027-06-28 Page title: Just a moment... ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-06-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:32:52 UTC (by PhishDestroy tracker) Last verified: 2026-07-27 07:00:43 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1d8-397d-768c-89e3-b5270f561dd8/ Wayback Machine: https://web.archive.org/web/*/lucenclouds.org crt.sh CT logs: https://crt.sh/?q=%25.lucenclouds.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=lucenclouds.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/lucenclouds.org URLhaus: https://urlhaus.abuse.ch/host/lucenclouds.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:35:27 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] lucenclouds.org Fake Cloud Storage Phishing Alert Analysis of lucenclouds.org indicates a high-risk phishing domain targeting cloud storage users. The domain was registered on June 28, 2025, through Sav.com, LLC, and remains active as of July 27, 2026. Infrastructure analysis reveals Cloudflare-hosted nameservers (arya.ns.cloudflare.com and damien.ns.cloudflare.com) and resolution to IP address 104.21.4.122, a common Cloudflare proxy endpoint. The domain appears on one security blocklist, with PhishDestroy currently blocking it. VirusTotal scans show 13 of 91 security vendors flagging the domain, though the specific detection rules or signatures are not detailed in available intelligence. No brand-specific targeting is confirmed in the provided data, though the domain name suggests an attempt to mimic legitimate cloud storage services. The exact content of the site has not been analyzed, so the precise phishing mechanism—whether credential harvesting, malware distribution, or another attack vector—remains unconfirmed. The use of Cloudflare nameservers and proxy IP is consistent with phishing campaigns seeking to obscure hosting origins and evade takedowns. Defenders should treat this domain as malicious based on blocklist inclusion and vendor detections. Network-level blocking of 104.21.4.122 and monitoring for connections to lucenclouds.org are recommended. If internal users report exposure, reset credentials for any cloud storage accounts accessed via this domain. Registrar contact with abuse reports may accelerate takedown, though Cloudflare's proxy complicates direct hosting provider intervention. Further analysis of HTTP headers, SSL certificates, or page content could clarify the attack chain, but current evidence supports immediate containment measures. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/lucenclouds.org/ JSON API: https://api.destroy.tools/v1/check?domain=lucenclouds.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,968 domains (78,390 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io