Analysis of sominxdocuments.net shows an infrastructure consistent with a newly created phishing site. The domain was registered on July 26, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is hosted on Cloudflare's network, using the nameservers harlan.ns.cloudflare.com and nola.ns.cloudflare.com. DNS resolution points to IP address 172.67.216.135, a Cloudflare edge node that does not reveal the underlying hosting provider.
The domain appears on a single security blocklist, PhishDestroy, indicating that at least one external monitoring service has flagged it as malicious. VirusTotal has processed the domain with scans from 91 antivirus vendors; at the time of analysis no vendor has issued a detection, though this absence of flags does not constitute a safety assurance. No additional public intelligence such as Safe Browsing entries, OTX reports, SSL certificate details, HTTP response codes, or page title information is currently available.
Consequently, the full scope of the campaign—including the targeted brand, credential‑stealing pages, or payload delivery mechanisms—remains unknown. Defenders should treat the domain as hostile: block DNS resolution to 172.67.216.135, add sominxdocuments.net to network and email allow‑list exclusions, and monitor for any related traffic patterns or credential submissions. Continuous re‑evaluation is advised, as further indicators such as content snapshots, additional blocklist listings, or vendor detections may emerge and refine the threat profile.