Analysis indicates that the domain valock.top is currently active and was registered on July 03, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The domain resolves to the IPv4 address 158.94.211.169 and is served by DNS resolvers a.dnspod.com, b.dnspod.com and c.dnspod.com. VirusTotal scans have recorded three positive detections out of ninety‑one participating security vendors, confirming that at least a subset of scanners consider the host malicious.
The domain is listed on one public security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, further corroborating its abusive nature. The risk rating assigned to the domain is high and the threat type is identified as generic phishing, indicating that the site is likely used to harvest credentials or other sensitive information. No additional intelligence such as SSL certificate details, HTTP response codes, Safe Browsing verdicts, or content analysis has been disclosed, leaving the exact content of the hosted pages unknown.
Consequently, defenders should treat valock.top as a hostile resource. Recommended actions include adding the domain and its resolving IP address to network deny lists, configuring DNS filters to block queries to the associated authoritative nameservers, and monitoring for any outbound connections to the host. Continuous re‑evaluation is advised, as further analysis of the web content or additional detection data may refine the threat profile.