The domain twcard.asia was registered on July 31, 2026 through Global Domain Group LLC and immediately pointed to the IP address 104.21.68.252. Its authoritative name servers are arvind.ns.cloudflare.com and naya.ns.cloudflare.com, indicating the use of Cloudflare’s DNS infrastructure. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy feed, confirming that at least one reputable anti‑phishing service has identified it as malicious.
VirusTotal records show that the domain was scanned by 91 security vendors, none of which reported a detection at the time of analysis; however, the absence of detections does not constitute evidence of safety. The domain remains listed as active, suggesting that threat actors may still be exploiting it. Defenders should treat twcard.asia as a high‑confidence phishing indicator.
Recommended controls include adding the domain to internal blocklists, monitoring DNS queries for the associated IP address and Cloudflare name servers, and employing URL filtering solutions that reference the PhishDestroy feed. Network traffic to 104.21.68.252 should be logged and, where possible, denied. Continuous re‑evaluation is advised, as additional detections or blocklist listings may emerge as the campaign evolves.