This domain, one-vv5095.life, is currently flagged as a high‑risk phishing resource. VirusTotal records show that 10 of 91 security vendors have identified it as malicious, indicating a moderate detection confidence across the scanning community. The domain was registered on 21 July 2026 through URL Solutions, Inc., and its DNS is delegated to Cloudflare nameservers (pranab.ns.cloudflare.com, robin.ns.cloudflare.com). Resolving the name returns the address 194.67.193.77, which is hosted on a Cloudflare edge node, a common tactic for threat actors to conceal the true hosting infrastructure.
The domain appears on one public security blocklist and is explicitly blocked by the PhishDestroy feed, confirming that at least one anti‑phishing organization has observed abusive activity linked to it. No public evidence such as page title, SSL certificate details, HTTP response codes, or Safe Browsing verdicts is presently available, so the content of the site remains unverified. The recent creation date, combined with the Cloudflare front‑end, suggests a short‑lived campaign designed to evade rapid takedown. Defenders should immediately block one-vv5095.life at DNS, proxy, and endpoint filtering layers, and also deny outbound connections to the resolved IP 194.67.193.77.
Adding the domain to internal blocklists and monitoring email gateways for references to the domain can reduce exposure to credential‑harvesting attempts. Because the domain is newly minted, any legitimate business traffic is unlikely; organizations should educate users to treat unexpected login or verification requests referencing this domain as malicious. Continuous monitoring of VirusTotal, PhishDestroy, and other threat‑intel feeds is recommended to capture any future detections or changes in reputation. Where possible, URL samples should be submitted to sandbox environments for behavioral analysis, which may reveal additional indicators such as downloader payloads or command‑and‑control endpoints.