The domain frontiertraders-spcx.com was registered on July 24, 2026 through Ultahost, Inc. and resolves to the IPv4 address 63.176.8.218. The authoritative name servers are dns1.p02.nsone.net through dns4.p02.nsone.net, indicating use of the NSONE hosting platform. Within hours of creation the domain was added to a public phishing blocklist and is currently blocked by the PhishDestroy service. VirusTotal scans show that one of ninety‑one security engines flagged the domain, confirming that at least one vendor has identified malicious behavior. No additional public blocklists or reputation services have listed the domain, and no Safe Browsing or OTX entries are present in the available intelligence.
The limited detection footprint suggests a newly deployed infrastructure that relies on fast‑flux or temporary hosting to evade early detection. Analysis of the infrastructure reveals no SSL certificate details, HTTP status codes, or page title information, so the content served by the site remains unverified. Consequently, the exact phishing campaign vector, targeted brand, or credential‑capture page layout cannot be confirmed at this stage. The short lifespan between registration and blocklisting, combined with the single vendor detection, is consistent with a high‑risk generic phishing operation that aims to harvest user credentials shortly after deployment.
Defenders should add frontiertraders‑spcx.com to local deny lists, enforce DNS‑based filtering, and monitor outbound connections to the hosting IP 63.176.8.218. Because the domain uses NSONE name servers, any future sub‑domains created under the same name‑server set may be part of the same campaign; continuous observation of the name‑server zone is recommended. Incident response teams should also correlate any authentication attempts or email links that reference the domain with user reports, and consider forcing password resets for accounts that may have been exposed.