Analysis of flicksverse.net shows a newly registered internet resource that aligns with typical phishing infrastructure. The domain was created on July 22, 2026 and is hosted on four UltraHost nameservers (ns1.ultahost.com through ns4.ultahost.com). DNS resolution points to IP address 192.142.53.169, a location commonly associated with shared hosting environments used for short‑lived malicious sites. Registration was performed through Fewmoretaps OU d/b/a Trustname.com, a registrar that appears in other threat‑intel reports for facilitating abuse.
VirusTotal records indicate the domain has been scanned by 91 antivirus and URL‑reputation vendors, none of which have issued a detection at the time of this review; this absence does not constitute a safety assurance. The domain is currently listed on one public security blocklist and is actively blocked by the PhishDestroy feed, confirming that threat‑intelligence communities consider the site malicious. No public evidence of SSL/TLS configuration, HTTP response codes, Safe Browsing verdicts, or page‑title metadata is available, leaving the exact content and credential‑harvesting mechanisms unverified.
Consequently, the primary observable indicators are the recent creation date, the UltraHost name‑server set, the registration details, and the inclusion in established phishing blocklists. Defenders should add flicksverse.net to network‑level deny lists, enforce DNS‑based blocking, and monitor outbound connections to the associated IP address. Continuous re‑scanning of the domain for content changes and periodic checks against URL‑reputation services are advised to capture any evolution of the site’s malicious payload.