Analysis of the domain inval.pro indicates it is an active phishing infrastructure registered on June 22, 2026, through Global Domain Group LLC. As of July 31, 2026, the domain resolves to the IP address 158.94.211.169 and is served by nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, suggesting potential ties to bulletproof hosting providers. Only 2 of 91 security vendors on VirusTotal have flagged this domain, reflecting limited detection coverage at present. The domain appears on one security blocklist, specifically PhishDestroy, which categorizes it as malicious.
No additional context regarding the targeted brand, phishing kit, or specific credential harvesting tactics is available from current intelligence. Defenders should treat this domain as high-risk due to its recent registration, active status, and confirmed blocklist presence.
Network-level blocking of 158.94.211.169 and inval.pro is recommended, along with monitoring for related DNS queries or outbound connections to this infrastructure. Further investigation into the site's content and associated campaigns is warranted to determine the exact phishing methodology and potential victim impact.