Analysis indicates that the domain firelight-rewards.live was registered on July 27, 2026 and resolves to the IPv4 address 172.67.179.182. The domain is delegated to Cloudflare name servers romina.ns.cloudflare.com and troy.ns.cloudflare.com, suggesting the use of Cloudflare’s DNS and CDN services for hosting. Registration was performed through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar that has been observed in other malicious campaigns, although no further attribution is available. The domain has been listed on a single security blocklist and is actively blocked by the PhishDestroy service, confirming that at least one defensive platform has identified it as malicious.
VirusTotal records show that the domain was scanned by 91 antivirus and URL‑reputation vendors, none of which raised a detection at the time of scanning; this lack of detections is not evidence of benign intent and should be interpreted as a potential evasion gap. No public information is available regarding SSL certificate details, HTTP response codes, page title, or any observed brand impersonation, leaving the exact content of the site unverified. Consequently, the primary observable indicators are the domain’s recent creation date, its Cloudflare infrastructure, the registrar used, and its presence on a blocklist.
Defenders should incorporate the IP address 172.67.179.182 and the domain firelight-rewards.live into URL filtering, DNS sinkhole, and intrusion‑detection rules. Continuous monitoring of threat‑intel feeds for any emergence of detection signatures, changes in blocklist status, or new analysis of the site’s payload is recommended. Organizations that employ outbound filtering should block connections to the domain and consider notifying users of potential phishing attempts associated with it, even though the specific target brand has not been identified.