The domain wwstash.com was registered on July 22, 2026 through Realtime Register B.V. and currently resolves to the IPv4 address 193.187.110.3. Its authoritative name servers are a.dnspod.com, b.dnspod.com and c.dnspod.com, indicating use of the DNSPod service. The domain appears on one public security blocklist and has been actively blocked by the PhishDestroy feed, confirming that multiple defensive platforms have identified it as malicious.
VirusTotal analysis shows that four of ninety‑one security vendors flag the domain, providing independent corroboration of its threat status. The domain is recorded as still active as of the report date, July 31, 2026, and is classified as a generic phishing site, suggesting it is being used to harvest credentials or other sensitive information. No additional data such as SSL certificate details, HTTP response codes, page titles, or brand targeting have been published, leaving the exact payload and victim‑facing content uncertain.
Defenders should prioritize immediate blocking of wwstash.com at perimeter firewalls and DNS resolvers, ingest the associated blocklist entries, and continue monitoring VirusTotal and other multi‑vendor feeds for any escalation in detection counts. Additional investigation of the hosting provider for IP 193.187.110.3 may reveal related infrastructure, and threat‑intel teams should consider sinkholing the domain to disrupt ongoing phishing operations while gathering further forensic evidence.