This domain, auspost.addqe.com, was registered on 29 July 2026 through Dominet (HK) Limited and is currently active. DNS resolution points to the IPv4 address 47.79.39.190 and the authoritative name servers are ns7.alidns.com and ns8.alidns.com. VirusTotal reports that 14 of 91 scanned security vendors have flagged the domain, indicating a moderate level of detection across the security ecosystem. The domain also appears on a single external blocklist and is listed as blocked by the PhishDestroy service, confirming that at least one independent feed has classified it as malicious.
No additional public reputation services, such as Google Safe Browsing or OTX, have been cited in the available intelligence, and no SSL certificate details or HTTP response codes have been disclosed, leaving those aspects unverified at this time. The rapid creation date, coupled with the use of a reputable DNS provider (Alibaba Cloud DNS) and a Hong‑Kong‑based registrar, is consistent with infrastructure commonly observed in short‑lived phishing campaigns. The limited detection footprint suggests that the campaign may be in an early stage of deployment, but the presence of multiple vendor detections demonstrates that existing detection mechanisms are already capable of identifying the host. Defenders should prioritize adding the observed IP address 47.79.39.190 to network‑level block lists and ensure that outbound connections to the two identified name servers are monitored for anomalous activity.
Email security gateways should be updated to flag any messages containing URLs that resolve to this domain, and URL filtering solutions should incorporate the domain into their deny lists. Given the lack of publicly available SSL or HTTP status information, analysts are encouraged to perform a controlled request to the host to capture response headers and certificate data, which can then be shared with threat‑intel communities to improve collective detection.