portal-flare[.]claims
The domain portal-flare.claims, now offline, was flagged as malicious by 3 out of 91 vendors on VirusTotal. This domain was quickly identified and added to public blocklists by PhishDestroy, MetaMask, and SEAL, highlighting its potential threat. The registrar NICENIC INTERNATIONAL GROUP CO., LIMITED facilitated its creation, with hosting provided by Cloudflare, Inc. Despite its takedown, the domain's initial activity posed a significant risk.
The phishing operation exploited the gap between domain registration and antivirus database updates, allowing it to operate under the radar briefly. PhishDestroy's detection pipeline identified the threat within days of its creation on May 28, 2026, emphasizing the domain's freshness rather than safety. The platform risk score of 68/100 further underscores its potential to deceive users.
The domain's page title, "Just a moment...", suggests an attempt to imitate a legitimate service, potentially misleading users into providing sensitive information. Although the domain is now offline, its presence in multiple blocklists serves as a reminder of its potential impact. The use of Let's Encrypt for SSL certification adds a layer of credibility that could have misled users into believing the site was secure.
Overall, portal-flare.claims represents a sophisticated phishing attempt that was swiftly neutralized. The collaboration between PhishDestroy and other cybersecurity entities played a crucial role in mitigating the threat. This case demonstrates the importance of early detection and rapid response in the fight against phishing attacks.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-19 03:17:10 UTC
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of portal-flare.claims · checked Jun 1, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive