Analysis of usdtguardaml.com shows a domain created on July 21, 2026 and registered through TUCOWS.COM, CO. The authoritative nameservers are chan.ns.cloudflare.com and lex.ns.cloudflare.com, indicating the use of Cloudflare's DNS service. DNS resolution points to the IP address 188.114.97.3, which is the sole host observed for this domain. The domain is currently listed on one security blocklist and has been blocked by the PhishDestroy service, confirming that it has been identified as malicious infrastructure.
VirusTotal records indicate that the domain was scanned by 91 antivirus and URL‑reputation vendors; at the time of the scan no vendor flagged the domain, though the absence of detections does not imply safety. No additional intelligence such as Safe Browsing status, OTX mentions, SSL certificate details, HTTP response codes, or page title information is available in the current dataset. The limited evidence points to a newly created phishing infrastructure that is actively serving content, but the lack of public detection by scanning engines suggests that the payload may be evading automated analysis or that the site is in an early deployment stage.
Defenders should consider proactively blocking the domain and its associated IP address at the network perimeter, adding the domain to internal URL filtering lists, and monitoring for any related traffic patterns. Continuous re‑evaluation is advised, as future scans may reveal detections or additional indicators of compromise. Until further content analysis is performed, the domain should be treated as a high‑confidence phishing threat based on its registration characteristics, blocklist presence, and active status.