The domain northforgeworks.com was registered on July 08 2026 through Ultahost, Inc. and is currently hosted on the IP address 188.114.96.3. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy service, indicating that at least one reputable anti‑phishing feed has classified it as malicious. VirusTotal records show that two of ninety‑one scanning engines have flagged the domain, providing additional independent confirmation of suspicious activity. The authoritative name servers are braden.ns.cloudflare.com and mina.ns.cloudflare.com, both belonging to Cloudflare’s DNS infrastructure, which is commonly used by both legitimate and malicious operators to leverage fast resolution and hide the true origin of the hosting provider.
Infrastructure analysis reveals no further publicly disclosed indicators such as SSL certificate details, HTTP response codes, or page titles; consequently the payload or content of the site remains unverified. The limited detection footprint—only one blocklist entry and two VT detections—suggests that the campaign may be in an early deployment stage or that monitoring coverage is sparse. Nonetheless, the combination of recent domain creation, association with a known phishing blocklist, and active blocking by PhishDestroy elevates the risk profile to high. Defenders should immediately add northforgeworks.com and its resolving IP 188.114.96.3 to deny lists across email gateways, web proxies, and endpoint protection solutions.
Ongoing DNS monitoring is advised to detect any future changes to the name‑server configuration or additional IP addresses that may be allocated to the domain. Where possible, threat‑intel platforms should be queried for any emerging reports that reference the same IP or Cloudflare name servers, as shared infrastructure can be indicative of broader phishing campaigns.