Analysis of the domain hopecharityorg.com indicates it is actively involved in a high-risk phishing operation targeting charitable donations. Registered on July 6, 2026, through Ultahost, Inc., the domain currently resolves to the IP address 192.142.10.5. Infrastructure analysis reveals the use of nameservers ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, and ns4.ultahost.com, suggesting centralized hosting control. The domain appears on one security blocklist and is blocked by PhishDestroy, though specific detection details from other vendors remain limited.
VirusTotal reports that 2 out of 91 security vendors flag this domain as malicious, providing partial but not conclusive evidence of its threat status. The exact content or target of the phishing site has not been fully analyzed, though the domain name implies a focus on charitable organizations. No evidence links it to a specific brand or phishing kit, and no additional context—such as HTTP response codes, SSL certificate details, or page titles—is available. Defenders should treat this domain as an active threat, particularly in environments where financial or donation-related transactions occur.
Network-level blocking of 192.142.10.5 and monitoring for connections to hopecharityorg.com are recommended. Further investigation into associated infrastructure, such as Ultahost’s hosting patterns, may reveal additional linked domains. Given its recent registration and limited detection coverage, this domain may represent an emerging campaign with evolving detection signatures.