Analysis of nhn-postsview.cafe indicates that the domain is actively used for phishing as of the report date, July 29, 2026. The domain was registered through Spaceship, Inc. and its creation timestamp is July 21, 2026, suggesting a rapid deployment timeline. DNS resolution points to the IPv4 address 34.111.179.208, and the authoritative nameservers are launch1.spaceship.net and launch2.spaceship.net, both belonging to the registrar’s infrastructure.
VirusTotal scans show that 7 of 91 security vendors have flagged the domain, providing independent confirmation of malicious intent. The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing its classification as a high‑risk phishing resource. Current monitoring indicates the domain remains active, with no evidence of mitigation or takedown.
No public SSL certificate details, HTTP response codes, or page‑title information are available, so the content and transport security posture remain unverified. Defenders should immediately add 34.111.179.208 to network‑level deny lists, enforce DNS filtering for nhn-postsview.cafe, and monitor the associated nameservers for any additional malicious domains. Continuous re‑evaluation of VirusTotal vendor detections and blocklist status is recommended to capture any changes in threat behavior.