The domain genesis-cloud.cc was registered on July 20, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently using Cloudflare name servers (arnold.ns.cloudflare.com and maria.ns.cloudflare.com). DNS resolution points to the IP address 172.67.173.246, which belongs to Cloudflare's global edge network and is commonly leveraged by threat actors to mask the true origin of malicious hosting. VirusTotal analysis shows that four out of ninety‑one security vendors have flagged the domain, indicating that multiple independent scanners have observed suspicious characteristics. The domain is listed on at least one public security blocklist and has been actively blocked by the PhishDestroy service, confirming that it is recognized by anti‑phishing infrastructure as a source of fraudulent activity.
No public page title, brand target, or specific phishing kit information is available in the current intelligence set, so the exact content served by the site remains unverified. However, the combination of recent registration, Cloudflare‑based hosting, vendor detections, and inclusion on blocklists aligns with typical infrastructure patterns used for generic phishing campaigns. Defenders should add genesis-cloud.cc to network and endpoint blocklists, enforce DNS sinkholing where possible, and monitor outbound connections to the associated IP address for signs of data exfiltration or credential submission.
Continuous re‑scanning of the domain against updated threat intelligence feeds is recommended to capture any changes in its hosting or payload delivery methods. Organizations should also consider employing URL filtering solutions that reference the latest blocklist entries to prevent user access. In the absence of a confirmed brand impersonation, the domain should be treated as a high‑risk phishing vector until further content analysis becomes available.