Analysis as of July 31, 2026 indicates that the domain veylorns.top was registered on June 18, 2026 through Global Domain Group LLC and is currently delegated to the DNSPod nameservers a.dnspod.com, b.dnspod.com and c.dnspod.com. The domain resolves to the IPv4 address 193.187.110.3, which is not associated with any known reputable service provider and appears on a single public security blocklist. PhishDestroy has actively blocked the domain, yet it remains listed as active in threat feeds. A recent VirusTotal scan submitted the domain to 91 anti‑malware engines; none of the engines reported a detection, but the absence of a flag does not constitute validation of safety.
The short lifespan of the domain, its recent creation date, and the lack of publicly visible reputation suggest it is being used for a credential‑harvesting campaign. No additional intelligence such as SSL certificate details, page title, or associated brand has been disclosed, leaving the exact phishing lure unknown. The lack of any published page content or SSL fingerprint prevents confirmation of the phishing vector, and the single blocklist entry does not provide insight into the specific campaigns targeting which brands.
Consequently, security teams should treat any email or web traffic referencing veylorns.top as potentially malicious, enforce multi‑factor authentication, and employ user education to reduce credential exposure. Defenders should continue to block veylorns.top at network perimeter and DNS filtering layers, monitor outbound connections to the associated IP address, and consider adding the domain to internal blocklists. Ongoing threat‑intel collection, including periodic re‑scans on VirusTotal and monitoring of passive DNS changes, will help determine if the domain escalates its activity or adopts new infrastructure.