Analysis of the domain valiu.top indicates that it is currently active and is being used for a generic phishing campaign. The domain was registered on 6 January 2026 through Global Domain Group LLC and is served by the DNS provider dnspod.com, as evidenced by the authoritative nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com. DNS resolution points to the single IPv4 address 193.187.110.3, which is the only host observed for this domain. The domain appears on at least one security blocklist; PhishDestroy has listed it as blocked, confirming that threat‑intelligence feeds are already aware of its malicious intent.
A VirusTotal scan performed by 91 anti‑malware engines returned no detections, however the absence of alerts does not constitute a safety guarantee, especially given the domain’s classification as a phishing infrastructure. No public information about SSL certificates, HTTP response codes, page titles, or content has been released, limiting the depth of the current analysis. Consequently, the primary observable indicators are the registration details, DNS configuration, hosting IP, and blocklist inclusion.
Defenders should add the domain and its resolved IP address to outbound filtering rules, monitor DNS queries for the listed nameservers, and ensure that any emails or web traffic referencing valiu.top are blocked or sandboxed for further inspection. Continuous re‑scanning of the domain on VirusTotal and other sandboxes is recommended, as the threat landscape may evolve and additional malicious payloads could be introduced. Organizations should also share any new artifacts with industry‑wide feeds to improve collective detection capability.