Analysis of lockercz.info, first observed on July 3 2026, shows it is actively serving a generic phishing campaign. The domain resolves to the IPv4 address 193.187.110.3, which is currently listed on a single public blocklist and is explicitly blocked by the PhishDestroy service. VirusTotal records indicate that three of ninety‑one scanned security vendors have flagged the domain as malicious, providing limited but corroborating evidence of abuse. Registration data ties the domain to Global Domain Group LLC, a registrar that frequently appears in malicious infrastructure, and the domain was created only weeks before the report date, suggesting a rapid deployment cycle.
Authoritative name servers are a.dnspod.com, b.dnspod.com, and c.dnspod.com, all operated by DNSPod, a widely used DNS hosting provider. No additional metadata such as SSL certificate details, HTTP response codes, or page titles have been published, leaving the exact content of the site unverified. The limited detection footprint, combined with the recent registration and active blocklist entry, points to a purposeful, short‑lived phishing operation. Defenders should prioritize immediate containment by adding lockercz.info to local deny lists, ensuring that any traffic to 193.187.110.3 is dropped, and monitoring for any related activity from the DNSPod name servers.
Continuous re‑scanning on VirusTotal and other multi‑engine platforms is recommended to capture any escalation in vendor detections. Organizations using email filters should also incorporate the domain into phishing rule sets to reduce exposure. Because the infrastructure is modest, further investigation of the hosting provider and any associated IP ranges may uncover additional malicious assets.