Analysis of the domain selecao-diadospais.com shows a newly registered phishing infrastructure that is actively serving malicious content. The domain was created on July 25, 2026 and is registered through GoDaddy.com, LLC, a registrar frequently leveraged by threat actors for rapid deployment. DNS resolution points to the IP address 143.95.223.155, and the authoritative name servers are ns05.domaincontrol.com and ns06.domaincontrol.com, both operated by GoDaddy’s DNS service. This hosting configuration is consistent with other short‑lived phishing sites that rely on shared hosting environments.
The domain appears on a single security blocklist and has been explicitly blocked by PhishDestroy, indicating that at least one security vendor has observed malicious use. VirusTotal scans have returned 12 positive detections out of 91 security vendors, confirming that multiple independent scanners recognize the site as malicious. Current status remains active, meaning the site continues to resolve and potentially host phishing payloads.
Concrete evidence about the page content, SSL certificate, or HTTP response headers is not yet available, leaving the exact phishing vector and targeted brand unspecified. Defenders should immediately add selecao-diadospais.com to URL filtering and DNS blocklists, monitor traffic to the associated IP 143.95.223.155, and consider correlating any authentication attempts to this domain with user reports. Continuous re‑evaluation is advised, as further analysis may reveal additional indicators such as page titles, targeted brands, or kit fingerprints that can enhance detection rules.