The domain valoflame.com was registered on June 17, 2026 through Web Commerce Communications Limited dba WebNic.cc and resolves to the IP address 158.94.211.169. Authority for the zone is provided by three dnspod.com nameservers (a.dnspod.com, b.dnspod.com, c.dnspod.com). The domain appears on a single security blocklist and has been flagged by the PhishDestroy blocklist, confirming that it is currently active in a phishing campaign. VirusTotal analysis shows that 15 out of 91 security vendors have marked the domain as malicious, indicating a consensus among a subset of scanners that the site hosts phishing content.
No additional public reputation services, SSL certificates, or HTTP response data are presently available, leaving the precise nature of the hosted payload unverified. The lack of corroborating page‑title or brand information means that the exact lure used in the phishing attempt cannot be determined from the existing data. Defenders should treat valoflame.com as a high‑risk indicator: block DNS resolution to the domain, deny outbound connections to its hosting IP (158.94.211.169), and include it in internal threat‑intel feeds.
Continuous monitoring of the associated IP and the dnspod.com name servers is recommended, as any changes may signal migration of the phishing infrastructure. Organizations employing email filters should add the domain to deny‑list rules and consider reviewing recent email traffic for messages that reference valoflame.com, especially those requesting credential submission. Because the domain is newly created and already shows multi‑vendor detection, rapid response is essential to mitigate potential credential harvesting or credential‑reuse attacks.