Analysis of horcheck.com indicates that the domain was registered on 25 April 2026 through Global Domain Group LLC. The authoritative name servers listed are a.dnspod.com, b.dnspod.com and c.dnspod.com, suggesting use of the DNSPod hosting service. DNS resolution points the domain to the single IPv4 address 193.187.110.3. The domain is currently marked as active and appears on one public phishing blocklist, specifically PhishDestroy, which has taken steps to block traffic to the host.
A VirusTotal scan performed by 91 antivirus and URL‑reputation engines returned no detections; however, the lack of a positive result does not constitute evidence that the site is benign. The combination of a recent registration date, use of a free DNS service, placement on a known phishing blocklist, and the absence of any publicly disclosed mitigation such as SSL/TLS certificates or reputable hosting identifiers raises a high likelihood that the domain is being leveraged for fraudulent activity. At present no public evidence of the site’s content, page title, or specific phishing kit has been disclosed, so the exact payload and target brand remain unknown.
The infrastructure analysis does not reveal additional co‑hosted domains or shared hosting patterns, limiting attribution. Defenders should consider adding horcheck.com to local deny lists, monitoring DNS queries for the associated IP address, and employing web‑filtering solutions that reference the PhishDestroy blocklist. Continuous re‑evaluation is advised, as the threat status remains "under investigation" and future detections may emerge.