This domain, tw-card-io-6f7362222253.herokuapp.com, is flagged as a high-risk generic phishing threat and remains active as of the July 31, 2026 report date. Infrastructure analysis shows the domain resolves to IP address 3.210.192.5, which is a hosting environment commonly used for Heroku applications. The domain was registered through Salesforce.com, Inc., the parent entity of the Heroku platform, and the subdomain structure is consistent with an auto-generated Heroku app identifier. No nameserver records were found for this domain, which is unusual for an active site and may indicate recent configuration changes or deliberate obfuscation of DNS details.
The domain appears on three independent security blocklists and is currently blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple security vendors have independently assessed this domain as malicious. The specific brand or page content has not yet been analyzed, so it is not possible to confirm what entity or service the site impersonates, but the domain naming pattern suggests a possible association with card-related services or financial platforms. Defenders should treat this domain as an active threat and ensure it is blocked at the network and email gateway levels. Users encountering this domain should avoid submitting any personal or financial information.
Given the active blocklist status and high-risk classification, organizations should add this domain to their deny lists and monitor for related subdomains or variations that may emerge. Further investigation is recommended to capture the page content, SSL certificate details, and any associated phishing kits. The absence of nameserver records and the reliance on a third-party hosting platform increase the likelihood that this domain is part of a broader phishing operation that may rotate through multiple similar subdomains to evade takedowns.