Analysis of discorddota.com shows a newly registered domain created on 26 July 2026 that is currently active and resolves to the IPv4 address 5.253.61.77. The authoritative name servers are ns1.adminvps.ru, ns2.adminvps.net, ns3.adminvps.ru, and ns4.adminvps.net, indicating hosting on infrastructure associated with the adminvps.ru/net namespace. Registration was performed through Fewmoretaps OU operating under the trade name Trustname.com. VirusTotal has recorded a single positive detection out of 91 scanned engines, confirming that at least one security vendor classifies the site as malicious.
The domain is listed on one external security blocklist and has been explicitly blocked by the PhishDestroy filtering service. No additional public intelligence such as Safe Browsing verdicts, Open Threat Exchange mentions, SSL certificate details, HTTP response codes, or page title information is presently available. The limited visibility suggests that the site may be used for a targeted phishing campaign, but the exact payload or credential‑harvesting mechanism remains unverified.
Defenders should add 5.253.61.77 and the full set of discorddota.com name servers to outbound filtering rules, enforce DNS sinkholing for the domain, and ensure that any email or web traffic to the site is denied. Monitoring of the IP address for sudden changes in hosting or additional detections is recommended, as is periodic re‑query of VirusTotal and other reputation services to capture any new classifications. Organizations that rely on corporate DNS resolvers should consider pre‑emptively blocking the domain at the resolver level to reduce exposure while investigations continue.