Analysis date: July 30, 2026. The domain persiasysco.ir is currently active and has been identified as a high‑risk generic phishing site. Infrastructure analysis shows the domain resolves to the IPv4 address 212.16.86.15 and is served by the authoritative name servers i.ns.arvancdn.ir and w.ns.arvancdn.ir. The hosting IP is listed on a single security blocklist and the domain is explicitly blocked by the PhishDestroy mitigation service.
Google Safe Browsing has flagged the domain for social engineering, indicating that it is likely used to harvest credentials or other sensitive information. VirusTotal records show that six out of ninety‑one scanning engines have raised detections against the domain, reinforcing the suspicion of malicious activity. Currently no SSL/TLS certificate information or HTTP response headers have been published, so the presence of HTTPS or specific server software cannot be confirmed. The limited public footprint suggests the operators may be using a transient hosting arrangement, but the persistent name server delegation to arvancdn.ir indicates a stable DNS configuration.
Analysts should treat the six VirusTotal detections as a moderate confidence indicator and prioritize this indicator alongside other high‑confidence sources such as PhishDestroy and Google Safe Browsing. Correlation with internal phishing email campaigns or compromised credential reports can help attribute any observed abuse to this domain. Sharing the indicator set—including the domain name, IP address, and name server details—with industry ISACs can improve collective defense. Continuous monitoring for changes in the domain's registration data, DNS records, or additional blocklist listings is advised, as threat actors frequently modify infrastructure to evade detection.