Analysis as of July 31, 2026 indicates that skytours-travels.com remains active and is currently classified as a generic phishing threat under investigation. The domain was registered on December 31, 2022 through OnlineNIC, Inc. and is delegated to the DNS service dnspod.com, using the authoritative name servers a.dnspod.com, b.dnspod.com, and c.dnspod.com. Resolution points to the IPv4 address 193.187.110.3, which is the sole host observed for this domain. The IP address is not listed in public ASN or geolocation data within the supplied intelligence, but the domain has been added to at least one security blocklist and is actively blocked by the PhishDestroy filtering service.
VirusTotal records show that the domain was submitted to 91 scanning engines, none of which reported a detection at the time of the scan. While the absence of detections does not constitute evidence of benign behavior, it does indicate that the payload or page content has not yet triggered signatures in the examined vendors. The limited detection footprint, combined with the early registration date and use of a free DNS provider, aligns with typical infrastructure choices observed in phishing campaigns that aim to reduce operational costs and increase turnover. Uncertainties remain regarding the actual content served by the site, the presence of SSL/TLS certificates, HTTP response codes, and any associated landing-page characteristics, because such details are not included in the current intelligence set.
Consequently, defenders cannot confirm whether the site is currently delivering credential-harvesting forms or other malicious payloads. Given the available evidence, security teams should continue to block skytours-travels.com at network perimeter and endpoint layers, monitor DNS queries for the associated dnspod.com name servers, and consider adding the domain to internal blocklists.