Analysis indicates that the domain lastdraftsec.online was registered through Namecheap Inc on June 09, 2026. The authoritative name servers are a.dnspod.com, b.dnspod.com, and c.dnspod.com, a configuration frequently observed in short‑lived malicious deployments because DNSPod services allow rapid updates and easy domain turnover. The domain resolves to the IPv4 address 158.94.211.169; no additional hosting details such as ASN or geographic location are disclosed in the available data. Reputation services have flagged the domain: PhishDestroy lists it as blocked, and it appears on one external security blocklist, indicating that at least one downstream filter has identified it as malicious.
VirusTotal reports that the domain was scanned by 91 antivirus and URL‑reputation engines, none of which generated a detection at the time of analysis. While the absence of detections does not constitute proof of safety, it suggests that the payload or landing page may be newly observed or employing evasion techniques that have not yet triggered signatures. No SSL/TLS certificate information, HTTP status codes, page title, or content snapshots are present, leaving the visual and functional characteristics of the site unknown.
Consequently, the primary evidence supporting a risk assessment consists of the recent creation date, the use of DNSPod name servers, the blocklist entries, and the classification as a generic phishing campaign. Defenders should consider proactively blocking lastdraftsec.online and its resolving IP address at perimeter and DNS filtering layers, monitoring for any related indicators of compromise, and updating detection rules to incorporate the observed infrastructure patterns. Continuous re‑evaluation is advised as additional telemetry, such as content hashes or observed payloads, becomes available.