glowcas.com was registered on July 24, 2026 through the registrar Fewmoretaps OU d/b/a Trustname.com. The domain is delegated to the Cloudflare nameservers destiny.ns.cloudflare.com and roman.ns.cloudflare.com and resolves to the IP address 172.67.213.113, which is part of Cloudflare’s edge network. Public threat intelligence shows the domain listed on a single security blocklist and it is actively blocked by the PhishDestroy feed. VirusTotal has processed the domain with 91 antivirus engines; none of the scanners reported a detection at the time of analysis.
No additional public analysis such as Safe Browsing, OTX, or SSL certificate details is available. The current operational status is marked as active, and the risk level remains under investigation. Analysis indicates that the domain’s short lifespan, recent creation date, and reliance on Cloudflare’s shared hosting are typical of infrastructure used for generic phishing campaigns. The lack of detections by AV engines does not imply benign intent, and the presence on a blocklist suggests that at least one security vendor has observed malicious activity associated with the domain.
Because the page content, HTTP response codes, and any observed credential‑stealing behavior have not been publicly disclosed, the precise phishing vector cannot be confirmed. Defenders should add glowcas.com to local deny lists, enforce DNS‑based blocking, and monitor outbound connections to the IP 172.67.213.113 for anomalous traffic. Continuous re‑evaluation of the domain on VirusTotal and other reputation services is advised, as additional detections may appear. Organizations should also review email filtering rules for messages that reference the domain, and consider employing URL‑rewriting or sandbox analysis for any links that resolve to it.