The domain tlr-finans.com was registered on 27 July 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolved to the Cloudflare edge address 172.67.162.124. Its authoritative name servers are hugh.ns.cloudflare.com and nia.ns.cloudflare.com, indicating that the infrastructure is hosted behind Cloudflare’s CDN and DDoS mitigation service. The domain appears on a single external security blocklist and is actively listed by PhishDestroy, confirming that threat‑intelligence feeds have identified it as malicious.
No public VirusTotal analysis is available, and the site has not been reported by other major scanning services, which does not imply benign intent. The lack of publicly disclosed TLS certificate details, HTTP response codes, page title, or Safe Browsing verdict means that the surface‑level content has not been captured in the current dataset. Nevertheless, the combination of recent registration, Cloudflare‑based hosting, and inclusion on a phishing‑specific blocklist aligns with typical patterns observed in newly‑created phishing infrastructure.
Defenders should add tlr-finans.com to network‑level deny lists, enforce DNS sink‑hole redirection, and monitor outbound traffic for connections to 172.67.162.124. Continuous re‑evaluation is advised, as further analysis of the web payload may reveal additional indicators of compromise.