The domain darkmatter-url.cyou was registered on July 25 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. Its authoritative name servers are adel.ns.cloudflare.com and javon.ns.cloudflare.com, indicating that the domain is hosted behind Cloudflare’s CDN network. DNS resolution points to the IP address 104.21.33.59, a Cloudflare edge node that masks the true backend server location. Within three days of creation the domain appeared on a security blocklist and is currently listed by PhishDestroy as an active malicious indicator.
VirusTotal analysis shows that one out of ninety‑one scanned scanners flagged the domain, confirming that at least one security product has identified it as suspicious. The limited detection coverage suggests that the payload or hosting may be newly deployed or that many scanners have not yet classified the activity. Publicly available intelligence does not include a page title, SSL certificate details, HTTP response codes, or any observed landing page content, leaving the specific phishing campaign or targeted brand unknown. Consequently, the exact threat vector—whether credential harvesting, malware delivery, or credential‑stealing redirects—cannot be confirmed at this time.
Defenders should immediately add darkmatter-url.cyou to outbound URL filtering and DNS block lists, and enforce network‑level denial of any connections to the resolved IP address 104.21.33.59. Continuous monitoring of DNS queries for this domain is advised, as the infrastructure may be reused for future campaigns. Analysts should also track the associated Cloudflare edge IP for any changes in reputation and consider sharing observed traffic with threat‑sharing communities to accelerate detection across broader ecosystems.