On July 31, 2026, the domain vaac.club was evaluated and assigned a high risk rating for generic phishing activity. The domain is currently active and appears on one known security blocklist. DNS resolution points to the IPv4 address 192.185.160.42, and authoritative name servers are listed as ns1129.websitewelcome.com and ns1130.websitewelcome.com, both belonging to the websitewelcome.com hosting platform. VirusTotal analysis shows that three of ninety‑one scanning engines have flagged the domain, indicating a modest but non‑trivial detection rate. The domain is also listed by the PhishDestroy blocklist, confirming its inclusion in at least one dedicated anti‑phishing feed.
No additional public intelligence such as SSL certificate details, HTTP response codes, or page title information is presently available, leaving those vectors unverified. The observed indicators suggest an infrastructure that leverages a shared hosting environment, which is common for low‑cost phishing sites. The modest detection count on VirusTotal may reflect limited exposure or recent deployment, but the presence on a phishing‑specific blocklist underscores the likelihood of malicious intent. Because the domain resolves to a single IP address, any mitigation that targets that address will affect all services hosted there, potentially impacting legitimate tenants.
Defenders should block DNS resolution to vaac.club and add the IP 192.185.160.42 to network‑level deny lists. Monitoring of outbound traffic for connections to this address is recommended, as is the inclusion of the domain in web‑proxy and email‑gateway deny lists. Continuous re‑scanning with VirusTotal and other sandbox services is advised to capture any evolution in payload or hosting changes. Until further content analysis is performed, the domain should be treated as hostile and excluded from user‑facing services.