The domain app-firelight.net was registered on July 30 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to the IP address 172.67.190.96 and is served by Cloudflare infrastructure, as indicated by the authoritative nameservers jo.ns.cloudflare.com and lex.ns.cloudflare.com. The rapid creation date and immediate activation suggest a purpose‑built malicious site. The domain is currently listed as active and has been blocked by the PhishDestroy community feed. It also appears on a single security blocklist, indicating that at least one external threat intelligence source has flagged it for malicious use.
VirusTotal analysis shows that one out of ninety‑one scanning engines returned a positive detection, confirming that the domain exhibits at least one observable indicator of compromise. The use of Cloudflare’s edge network masks the true origin of the hosting server, but the public IP 172.67.190.96 is associated with Cloudflare’s global content delivery network, a common choice for phishing operators seeking to hide backend infrastructure. No additional data such as SSL certificate details, HTTP response codes, or page titles have been published, so the visual content and specific credential‑harvesting technique remain unknown. Given the limited but concrete evidence—recent registration, Cloudflare hosting, a positive vendor detection, and inclusion on a phishing blocklist—defenders should treat app-firelight.net as a high‑risk phishing vector. Recommended mitigation steps include adding the domain to DNS‑based deny lists, configuring web proxies to block HTTP requests to the address, and monitoring outgoing traffic for connections to the associated Cloudflare IP.
Incident response teams should also correlate any authentication attempts from internal users with the timestamp of the domain’s creation to identify potential compromise. Analysts should continue to collect passive DNS, SSL, and page‑title data to refine the profile.