This domain, verrlfymax.com, is under investigation as a generic phishing threat as of August 01, 2026. The domain was created on July 31, 2026, and is currently active. It is registered through CNOBIN INFORMATION TECHNOLOGY LIMITED, a registrar that has been associated with other malicious domains in the past. The domain resolves to IP address 85.239.144.149, which is a hosting infrastructure commonly used for phishing operations. The nameservers are dom.ns.cloudflare.com and kinsley.ns.cloudflare.com, indicating the use of Cloudflare's DNS services, which can help obscure the true origin of the hosting.
The domain has been blocked by PhishDestroy, a security vendor, and appears on one security blocklist, confirming that at least one threat intelligence source has flagged it as malicious. VirusTotal has scanned the domain with 91 vendors, and currently zero vendors flag it as malicious. This absence of detections is not proof that the domain is safe, as it may be a newly registered domain that has not yet been widely analyzed or may be using evasion techniques to avoid detection. The exact content of the website is not yet analyzed, so the specific brand or type of phishing campaign it is running is unknown. The domain's recent creation date, combined with its registration through a high-risk registrar, its resolution to an IP address associated with malicious activity, and its presence on a blocklist, suggests that it is likely part of a phishing campaign.
Defenders should treat this domain as a potential threat and block access to it at the network level. They should also monitor for any connections to this domain in their logs and investigate any users who may have interacted with it. Additionally, they should consider adding the IP address 85.239.144.149 to their threat intelligence feeds and blocklists, as it may be used to host other malicious domains.