Analysis of investecsafety.com, registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, shows the domain was created on July 27, 2026 and remains active as of the report date, July 31, 2026. DNS resolution points to the IP address 172.67.143.208, which is owned by Cloudflare's network, and the domain uses Cloudflare nameservers cosmin.ns.cloudflare.com and karsyn.ns.cloudflare.com. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy service, indicating that at least one threat‑intelligence feed has identified it as malicious.
VirusTotal records show the domain has been scanned by 91 antivirus and URL‑reputation vendors, yet none have raised a detection at the time of scanning; this absence of alerts does not constitute evidence of safety and should be interpreted cautiously. No public information about the site’s SSL certificate, HTTP response codes, page title, or content has been disclosed, so the surface‑level characteristics of the landing page remain unverified. Given the recent registration date, use of a reputable CDN provider, and inclusion on a phishing‑specific blocklist, the domain aligns with patterns observed in generic phishing campaigns that leverage fast‑changing infrastructure to evade early detection.
Defenders should add investecsafety.com to network‑level deny lists, monitor DNS queries for connections to 172.67.143.208, and enforce URL filtering policies that block access to the domain. Continuous re‑scanning on platforms such as VirusTotal is advised, as future analyses may reveal payloads or malicious redirects not present at the initial scan. Organizations should also consider sharing any observed traffic or payloads with threat‑intel communities to improve collective detection of this emerging phishing infrastructure.