Analysis of line.quicktent.org indicates that the domain was registered on May 26, 2026 through the registrar Fewmoretaps OU operating under the trade name Trustname.com. The authoritative nameservers ares.trustname.com and zeus.trustname.com resolve the zone to the IPv4 address 91.229.239.28. At the time of review the domain appears on two independent security blocklists and is actively blocked by the PhishDestroy and ScamSniffer filtering services, confirming that it is currently being treated as malicious by external threat‑intelligence feeds. VirusTotal recorded a scan of the domain by 91 commercial and open‑source scanners; none of the engines raised a detection at the moment of scanning. While the absence of flags does not constitute evidence of benign intent, it demonstrates that the payload or hosting characteristics have not yet matched known signatures.
No public Safe Browsing, OTX, or SSL certificate details were available, and the HTTP response code and page title have not been captured in the current intelligence set. The limited data set leaves several open questions. The specific phishing template, targeted brand, and any credential‑harvesting mechanisms remain undisclosed, as no page‑level analysis has been published. Likewise, the geographic location of the hosting provider and the autonomous system number associated with 91.229.239.28 have not been disclosed, limiting attribution efforts.
Defenders should continue to block the domain at network perimeter devices and update proxy or DNS filtering policies to include the identified blocklist entries. Periodic re‑scanning on VirusTotal or similar multi‑engine platforms is recommended to capture any future classification changes. Monitoring of the associated IP address for anomalous traffic patterns and correlating logs against the known nameservers may provide early indicators of related campaigns. Given the active blocklist status, inclusion of line.quicktent.