Analysis as of July 31, 2026 indicates that the domain valothai.sbs remains active and is being used for generic phishing campaigns. The domain was registered on March 04, 2026 through Global Domain Group LLC and is hosted on the nameservers a.dnspod.com, b.dnspod.com and c.dnspod.com. DNS resolution points the domain to the IPv4 address 158.94.211.169. The IP address is currently listed on a single security blocklist and has been flagged by the PhishDestroy sinkhole, confirming its involvement in malicious email or web‑based credential harvesting.
VirusTotal reports that 12 of 91 scanning engines have generated a malicious verdict for the domain, reinforcing the suspicion that the site hosts phishing content. No additional public intelligence such as SSL certificate details, page title, or brand targeting is available at this time, limiting the ability to attribute the campaign to a specific lure or kit. The lack of further contextual data suggests that the infrastructure is being used in a lightweight, possibly short‑lived campaign that relies on rapid domain turnover.
Defenders should ingest the domain and its resolved IP address into network‑level deny lists, update DNS filtering policies to block any query for valothai.sbs, and monitor traffic to 158.94.211.169 for anomalous authentication attempts. Continuous re‑scanning on VirusTotal and other multi‑engine platforms is recommended to capture any changes in detection rate. Given the active status and the observed malicious indicators, the risk posture for this domain should be considered high.