Analysis indicates that the domain phone-lcloud.site was registered through EuroDNS S.A. on July 5, 2026 and is presently active. DNS resolution points to the IPv4 address 108.167.146.200, which is hosted on infrastructure that uses the nameservers cns43.webhostbox.net and cns44.webhostbox.net. The domain appears on two public security blocklists and has been specifically listed by PhishDestroy and OpenPhish, confirming its classification as a phishing resource.
VirusTotal scanning shows that one out of ninety‑one antivirus and URL scanners flagged the domain, providing additional corroboration of malicious intent. No further public intelligence such as page title, SSL certificate details, HTTP response codes, or associated malware families has been disclosed, leaving the exact content and targeted brand indeterminate. Defenders should prioritize blocking network connections to 108.167.146.200 and adding phone-lcloud.site to local deny lists.
Security appliances that integrate threat feeds from PhishDestroy, OpenPhish, or VirusTotal should be updated to reflect the current listings. Continuous monitoring of DNS queries for the domain and its authoritative name servers is advised to detect any future shifts in hosting or additional malicious payloads. Given the recent creation date and active status, the domain should be treated as high‑risk until further forensic analysis confirms its behavior.