Analysis of the domain mybt-payment-107385-109649.square.site shows a high‑risk phishing infrastructure that remains active as of 31 July 2026. DNS resolution points to the IPv4 address 74.115.51.5, and the domain lacks publicly visible nameserver records (NS_NOT_FOUND), suggesting either a deliberately hidden DNS configuration or a recent change that has not propagated. The registrar listed for the domain is Square, Inc., a legitimate e‑commerce platform, indicating that the domain was likely created through a legitimate registration channel but then repurposed for malicious use.
Threat intelligence indicates that the domain is listed on a single security blocklist, specifically PhishDestroy, which has already taken action to block the host. VirusTotal scans have returned detections from 11 of 91 participating security vendors, reinforcing the suspicion of malicious activity despite the relatively low overall detection ratio. No additional evidence such as SSL certificate details, HTTP response codes, page titles, or Safe Browsing verdicts is currently available, leaving the exact content and delivery mechanisms of the site unverified.
Defenders should treat this domain as a confirmed phishing source: block it at network perimeters, add it to URL filtering and DNS sinkhole lists, and monitor for any outbound connections to the associated IP address. Continuous re‑evaluation is advised, as the lack of visible nameserver data and limited public analysis create uncertainty about potential changes in hosting or content. Organizations using Square services should be aware that legitimate registration channels can be abused, and should enforce multi‑factor authentication and user education to mitigate credential‑theft attempts that may reference this domain.