Sterlingvests.com is flagged as a high‑risk generic phishing infrastructure. The domain was registered through Ultahost, Inc. and uses four authoritative nameservers (ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, ns4.ultahost.com). It was created on July 03, 2026 and remains active on the reporting date of July 30, 2026. DNS resolution points to the single IPv4 address 159.100.6.5, which is the only known hosting endpoint for the observed activity.
The domain appears on one security blocklist and is actively blocked by the PhishDestroy sink‑hole service, indicating that at least one defensive feed has identified it as malicious. VirusTotal analysis shows that four of ninety‑one scanning engines have raised detections against the domain, providing independent confirmation of its suspicious nature. No public page title, SSL certificate details, or HTTP response codes have been disclosed, so the exact content served by the site cannot be verified at this time.
The lack of additional contextual indicators such as brand impersonation or payload specifics limits attribution, but the combination of recent registration, single‑IP hosting, blocklist presence, and multiple vendor detections meets the criteria for a high‑confidence phishing indicator. Defenders should immediately add 159.100.6.5 and the domain name sterlingvests.com to outbound and inbound deny lists, monitor DNS queries for the four listed nameservers, and consider sinkholing the IP to prevent further credential harvesting. Continuous re‑analysis is advised to capture any emerging page content, certificate changes, or additional vendor detections that may refine the threat profile.