Analysis of in2uhrkr.com indicates an active phishing domain registered on July 21, 2026, through NameSilo, LLC. The domain resolves to IP address 185.199.108.153 and is currently hosted on nameservers ns1.dnsowl.com, ns2.dnsowl.com, and ns3.dnsowl.com. As of July 29, 2026, the domain appears on one security blocklist and is blocked by PhishDestroy, suggesting early detection of malicious intent. No vendor detections were recorded in a VirusTotal scan involving 91 security engines, though the absence of flags does not confirm safety.
Infrastructure review shows the domain remains operational, with no evidence of takedown or suspension. The registration date, less than ten days prior to this report, aligns with common phishing domain lifecycle patterns, where rapid deployment and short-lived activity are typical. The lack of brand-specific indicators or confirmed scam type in available data limits classification to a generic phishing threat.
Defenders should treat this domain as suspicious based on its recent registration, hosting on a known bulletproof provider, and presence on a security blocklist. Further monitoring is recommended to assess evolving detection coverage and potential targeting patterns. No confirmed brand impersonation or specific phishing kit has been identified at this stage.