Analysis of layerzero-whitelist.top shows a newly registered domain created on 31 July 2026 through the registrar Spaceship, Inc. The domain resolves to the IPv4 address 75.2.60.5 and is served by the authoritative name servers launch1.spaceship.net and launch2.spaceship.net. It is listed on three public blocklists—PhishDestroy, MetaMask, and SEAL—indicating that multiple threat‑intelligence feeds have flagged the domain for phishing‑related activity. A VirusTotal scan performed by 91 antivirus and URL‑reputation engines returned no detections; this lack of a positive result does not confirm that the domain is safe.
No SSL certificate details, HTTP status codes, page‑title information, or additional hosting metadata have been published, so the content hosted on the site remains unknown. The limited observable infrastructure suggests an attempt to keep the operational footprint small while the campaign is active. Defenders should block the domain at DNS and proxy layers, incorporate the three blocklist entries into their threat‑feed subscriptions, and monitor traffic to the IP address 75.2.60.5 for anomalous authentication attempts.
Continuous re‑scanning with VirusTotal or comparable services is recommended to capture any future changes in detection status. Organizations that rely on services referenced by the blocklists (for example, MetaMask) should treat any credential submissions to this domain as compromised and enforce password‑reset procedures. Because the domain is only one day old, additional intelligence such as page content, SSL usage, or further hosting details may emerge; analysts should update detection rules as new indicators become available.