Analysis of the domain gram.qpon shows a recently registered Internet resource that is already being leveraged for malicious activity. The domain was created on July 06, 2026 and registered through Global Domain Group LLC, a registrar known to host a variety of short‑lived domains. DNS resolution is handled by three dnspod.com nameservers (a.dnspod.com, b.dnspod.com, c.dnspod.com), and the A record points to the IPv4 address 193.187.110.3. No additional records such as MX or TXT have been observed in public queries, and no SSL/TLS certificate information is publicly available, indicating that the site may be operating over HTTP or that certificate data has not been harvested.
The domain has been flagged by the PhishDestroy blocklist and appears on one additional security blocklist, confirming that at least one independent threat intelligence source has identified it as malicious. VirusTotal reports that the domain was scanned by 91 antivirus and URL‑reputation engines, none of which raised a detection at the time of analysis; however, the absence of detections does not constitute evidence of safety, especially given the rapid emergence of the domain. No page title, brand target, or specific phishing kit information has been disclosed, so the exact content and the victim‑facing lure remain unknown.
Consequently, the current confidence is that gram.qpon is being used for a generic phishing campaign, but the precise payload and impersonated entity cannot be confirmed without further forensic capture of the landing page. Defenders should add the IP address 193.187.110.3 and the domain gram.qpon to outbound and inbound blocklists, monitor DNS queries for the domain and its authoritative name servers, and continue to collect any HTTP response data that may become available. Ongoing observation of the dnspod.com name server cluster is recommended, as these servers frequently host other malicious domains that can be re‑used in future campaigns.