Analysis of the domain elyndorgroup.com, created on July 02, 2026 and hosted on the IP address 139.59.183.219, indicates infrastructure consistent with a newly deployed phishing campaign. The domain is registered through Ultahost, Inc. and uses DigitalOcean’s authoritative name servers (ns1.digitalocean.com, ns2.digitalocean.com, ns3.digitalocean.com). VirusTotal records show that the domain has been examined by 91 independent scanning engines, none of which have raised a detection at the time of review.
Despite the lack of vendor flags, the domain appears on a single external blocklist and has been explicitly blocked by the PhishDestroy service, suggesting that independent threat‑intelligence feeds have identified malicious activity associated with the host. The current public status is listed as active, and the risk level is noted as “under investigation,” reflecting limited visibility into the payload or victim targeting. Observable evidence does not include SSL certificate details, HTTP response codes, page titles, or any brand references, leaving the exact content of the site unconfirmed.
Defenders should treat the domain as potentially malicious, enforce network‑level blocks against both the domain and its resolving IP, and continue to monitor for any changes in detection status, additional blocklist listings, or emerging intelligence that could clarify the threat vector. Ongoing vigilance is recommended given the recent registration date and the active classification by existing blocklists.