This domain, canyonsignalworks.com, was registered on July 06, 2026 through Ultahost, Inc. and is hosted on Cloudflare infrastructure, resolving to the IPv4 address 172.67.165.218. The authoritative name servers listed are fatima.ns.cloudflare.com and memphis.ns.cloudflare.com, indicating that the domain is fully delegated to Cloudflare’s DNS service. The site has been flagged by the PhishDestroy blocklist and appears on one additional security blocklist, confirming that at least one trusted threat‑intelligence feed considers it malicious. VirusTotal records show that the domain was scanned by 91 anti‑malware vendors; none reported a detection at the time of analysis, but the absence of detections does not equate to safety and reflects the limited visibility of static URL checks.
No public Safe Browsing, OTX, or SSL certificate details were supplied in the current intelligence set, and the page title has not been captured, leaving the exact phishing lure undefined. The rapid creation date—less than a month before the report date—combined with the use of a reputable CDN suggests a typical “throwaway” phishing infrastructure designed to evade reputation buildup. The IP address belongs to Cloudflare’s edge network, which can host multiple unrelated domains, so attribution based solely on the IP is unreliable.
Defenders should treat canyonsignalworks.com as a confirmed phishing indicator. Immediate actions include adding the domain to DNS and proxy blocklists, enforcing outbound filtering for the associated IP range, and monitoring for any related C2 patterns that may emerge. Continuous re‑evaluation is advised, as additional telemetry such as HTTP response codes, SSL fingerprint, or observed credential‑stealing pages could surface and refine the threat profile.