qvalo[.]top
Analysis of the domain qvalo.top shows it was registered on May 31, 2026 through Global Domain Group LLC and is currently hosted on IP address 193.187.110.3. The authoritative name servers are a.dnspod.com, b.dnspod.com, and c.dnspod.com, indicating use of the DNSpod service. VirusTotal scans have flagged the domain by three of ninety‑one security vendors, suggesting malicious behavior despite a relatively low detection count. The domain remains active as of the report date, July 15, 2026, and is classified as a high‑risk generic phishing threat. No public page content, landing page details, or targeted brand information have been released, so the exact phishing vector and victim profile are uncertain. Defenders should treat qvalo.top as a credential‑harvesting infrastructure, block outbound connections to the associated IP, and add the domain and its name‑server set to network‑level deny lists. Continuous monitoring of DNS queries for the domain and periodic re‑scans on threat‑intel platforms are recommended to detect any escalation in malicious activity.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
PD-20260715-4B391A Recipient: abuse@cyberaegis.casa Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive