Analysis of the domain valoratent.shop, observed on 31 July 2026, indicates that it is actively being used for generic phishing operations. The domain resolves to the IPv4 address 158.94.211.169, which is the sole A record returned by DNS queries. Authoritative name servers are listed as a.dnspod.com, b.dnspod.com, and c.dnspod.com, confirming registration through the DNSPod service. Multiple independent security feeds have flagged the domain: PhishDestroy has added it to its blocklist, and it appears on one additional security blocklist. VirusTotal scans show that four of ninety‑one antivirus or URL‑reputation engines have raised detections against the domain, reinforcing the suspicion of malicious activity.
The aggregate risk rating assigned by the reporting system is high, and the domain’s status remains active at the time of analysis. No public information about the registrar, registration date, or SSL certificate details is available in the supplied data, limiting the depth of infrastructure profiling. The lack of a published page title or explicit brand targeting means that the specific lure employed by the site cannot be confirmed without further content inspection. Because the site’s content has not been captured in the current intelligence set, the exact phishing vector—such as credential harvesting page or malicious download—remains unknown. Nevertheless, the convergence of DNS pointing to a single IP, presence on a dedicated phishing blocklist, and multiple vendor detections provides sufficient evidence for security teams to treat valoratent.shop as a confirmed phishing host.
Threat actors may be leveraging the dnspod.com infrastructure to quickly spin up additional domains, a pattern observed in other campaigns that use similar name‑server configurations. Defenders should block network connections to 158.94.211.169 and add valoratent.shop to domain‑based deny lists across perimeter firewalls, secure web gateways, and endpoint protection solutions.