The domain geldboost24.com was registered on July 12 2026 via the registrar Ultahost, Inc. Its authoritative name servers are ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com and ns4.ultahost.com, all of which resolve the domain to the single IPv4 address 173.211.81.11. The hosting IP is currently listed on one public security blocklist and has been added to the PhishDestroy blocklist, indicating that at least one upstream mitigation service is already denying traffic to the host. VirusTotal analysis shows that 2 of 91 scanned security engines flagged the domain as malicious, confirming that automated scanners have observed suspicious behavior consistent with phishing.
The domain is classified in the intelligence feed as a generic phishing site and is marked with a high risk rating; its operational status remains active as of the report date, July 30 2026. Analysis of the available artifacts does not reveal a page title, SSL certificate details, or any brand‑specific lure, so the exact content served by the site has not been publicly disclosed. The limited detection footprint—only two vendor detections and a single blocklist entry—suggests that the infrastructure may be newly deployed or otherwise low‑profile, but the presence of a dedicated phishing blocklist entry demonstrates that threat actors are actively using the domain for credential‑harvesting campaigns.
Defenders should add 173.211.81.11 to network‑level deny lists, enforce DNS sink‑hole rules for geldboost24.com, and monitor outbound connections to the Ultahost name‑server cluster for any anomalous queries. Endpoint security solutions should be updated to include the domain in URL reputation filters, and any user‑initiated traffic to the domain should be blocked or quarantined pending further investigation. Continuous re‑scanning of the domain on VirusTotal and periodic checks against emerging blocklists are recommended to capture any escalation in detection activity.