Analysis of the domain valvex.top indicates a high‑risk, active phishing operation. The domain was registered through Global Domain Group LLC and created on 16 June 2026, suggesting a very recent deployment that aligns with the observed high‑risk classification. DNS resolution points to the IPv4 address 158.94.211.169, and the authoritative name servers are listed as a.dnspod.com, b.dnspod.com, and c.dnspod.com, a configuration commonly used by fast‑flux or disposable hosting services.
The domain appears on a single security blocklist and is currently blocked by the PhishDestroy service, confirming that at least one external threat‑intelligence feed has identified it as malicious. VirusTotal scans show that three of ninety‑one security vendors have flagged the domain, providing independent corroboration of suspicious activity despite the relatively low detection count. No additional public intelligence—such as Safe Browsing alerts, OTX mentions, SSL certificate details, HTTP response codes, or page‑title information—has been disclosed, leaving the precise phishing payload or targeted brand unverified.
Defenders should immediately block DNS resolution to 158.94.211.169, add valvex.top to local deny lists, monitor traffic for connections to the listed dnspod name servers, and consider broader network‑wide phishing detection rules that capture newly registered, high‑risk domains. Continuous re‑evaluation is advised, as further evidence may emerge from additional scanning or victim reports.