On July 28, 2026, analysis flagged badge-free-lifetime-verified.surge.sh as an active generic phishing infrastructure. The domain is hosted on the Surge.sh platform and resolves to the IPv4 address 159.203.159.100. VirusTotal has recorded 19 positive detections out of 91 scanned security vendors, indicating that multiple anti‑malware engines have identified malicious behavior associated with the host. The domain is currently listed on a public security blocklist and has been explicitly blocked by the PhishDestroy mitigation service.
DNS queries return a placeholder response of NS_NOT_FOUND for the authoritative nameserver, suggesting that the domain relies on Surge.sh’s default DNS configuration rather than a custom delegation. No additional metadata such as SSL certificate details, HTTP status codes, or page title information is available in the supplied intelligence, leaving the content of the landing page unverified. The lack of a recorded page title or brand target means that the specific lure employed by the site cannot be confirmed at this time.
Defenders should continue to monitor the IP address 159.203.159.100 for any outbound connections originating from internal hosts and enforce existing URL filtering rules that include the observed blocklist entry. Adding the domain to local deny lists and ensuring that PhishDestroy or equivalent anti‑phishing solutions remain active will help prevent end‑user exposure. Because the registrar information is limited to the Surge.sh service, attribution beyond the hosting provider is not currently possible, and further investigation may be required to uncover any additional command‑and‑control nodes or associated domains.