The domain itupa.com was registered through Gname.com Pte. Ltd. on April 19, 2014 and continues to resolve to the IP address 143.204.181.13. Infrastructure analysis shows that the domain is served by four authoritative name servers (a.share-dns.com, a8.share-dns.com, b.share-dns.net, b8.share-dns.net), a configuration commonly observed in fast‑flux or shared‑hosting environments used by malicious operators. The domain appears on three public security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, indicating that multiple anti‑phishing platforms have identified it as malicious.
VirusTotal scanning reports five of ninety‑one security vendors flagging the domain, providing additional vendor‑level corroboration of its threat status. No public Safe Browsing, Open Threat Exchange, or SSL/TLS certificate data is available for this domain, and HTTP response details have not been disclosed, leaving those vectors unverified. The evidence collectively points to a high‑risk, active generic phishing campaign.
Defenders should add itupa.com to outbound and inbound filtering rules, monitor DNS queries for the associated IP and name servers, and consider sinkholing the domain where possible. Users should be warned not to interact with any links or emails referencing itupa.com, and security teams should continue to track any changes in detection counts or blocklist status to adjust response posture accordingly.