valput[.]top
“VALORANT: Riot Games”
Analysis of valput.top indicates that the domain was registered on July 17, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The domain is served by Cloudflare nameservers seamus.ns.cloudflare.com and treasure.ns.cloudflare.com and resolves to the IPv4 address 192.162.199.233. Within three days of creation the domain was added to a security blocklist and is currently blocked by the PhishDestroy service, reflecting rapid detection by threat‑mitigation platforms. VirusTotal reports that 2 of 95 scanned security vendors have flagged the domain, confirming that at least a small subset of scanners consider it malicious. The limited detection count suggests that the payload or landing page may not yet be widely distributed, but the presence of any positive detections combined with the blocklist entry and the high‑risk classification supplied by the reporting source warrant immediate defensive action. No additional intelligence such as SSL certificate details, HTTP response codes, or page‑title information is available, leaving the precise content of the site unknown. Defenders should therefore treat the domain as a high‑confidence indicator of a phishing campaign, enforce network‑level blocking of the domain and its resolved IP address, monitor for any related DNS queries, and consider adding the domain to internal blocklists. Ongoing observation of future VirusTotal scans and blocklist updates is recommended to capture any escalation in detection counts or the emergence of new malicious infrastructure associated with valput.top.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Threat Intel Cross-Reference · source references
Technologies · 5 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% confidencejQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% confidenceGoogle Hosted Libraries is a stable, reliable, high-speed, globally available content distribution network for the most popular, open-source JavaScript libraries.
developers.google.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Evidence & External Reports
PD-20260720-1EC290 Recipient: abuse@as214351.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive