Analysis of the domain separate-apricot-hbdffwuz.edgeone.dev, registered through Tencent Cloud, indicates active phishing infrastructure as of July 29, 2026. The domain resolves to the IP address 43.174.246.29, with no nameservers detected at the time of investigation, a configuration often observed in ephemeral or rapidly deployed malicious infrastructure. It appears on a single security blocklist, specifically PhishDestroy, which has flagged it for phishing-related activity. No detections were recorded by the 91 vendors that scanned the domain on VirusTotal, though the absence of detections does not confirm benign intent and may reflect delayed or incomplete coverage. The domain remains active, with no evidence of takedown or deactivation.
Infrastructure analysis reveals hosting under Tencent Cloud, a provider frequently utilized for both legitimate and malicious operations. The lack of nameserver records may suggest automated or low-effort deployment, a common tactic in phishing campaigns to evade detection and facilitate rapid rotation of domains. No specific brand impersonation, page title, or scam type has been identified in the available data, and the exact content of the site has not been analyzed. Defenders are advised to treat this domain as suspicious based on its presence on a phishing blocklist and its technical indicators.
Network-level blocking of the domain and its resolving IP (43.174.246.29) is recommended pending further analysis. Monitoring for additional detections or blocklist additions should be prioritized, as this domain may represent part of a larger, evolving phishing campaign. No SSL certificate details or HTTP response data were provided, limiting assessment of encryption or server behavior. Further investigation into associated infrastructure, such as co-hosted domains or historical DNS records, may yield additional context.