The domain statesfederalunion.com was registered on July 05 2026 through Ultahost, Inc. and is currently resolved to the IPv4 address 159.100.6.19. The authoritative name servers for the zone are ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, and ns4.ultahost.com, indicating that the infrastructure is hosted by the same provider that supplied the registration. VirusTotal reports that four of ninety‑one scanning engines have flagged the domain, confirming that a minority of security products have detected malicious activity associated with it. Independent reputation services have placed the domain on a single security blocklist and the anti‑phishing service PhishDestroy lists it as blocked.
The threat classification supplied by the intelligence source is "generic phishing" with a high risk rating and an active status. These observable indicators collectively suggest that the domain is being used in a phishing campaign, although the specific content of the hosted pages has not been publicly disclosed. The limited number of detections may reflect recent creation, low exposure, or evasion techniques, but the presence on a dedicated phishing blocklist and the active block by PhishDestroy provide concrete evidence of malicious intent.
Defenders should add 159.100.6.19 and the full set of ultahost name servers to their deny lists, enforce domain‑level blocking for statesfederalunion.com, and monitor for any new resolution changes. Because the registration information is public and the hosting provider is known, threat‑intel teams can also consider contacting Ultahost for takedown assistance. Continuous observation of VirusTotal and other multi‑engine scanners is recommended to capture any increase in detection counts, which would further confirm the operational status of the campaign.