Analysis of sinport.org shows that the domain was registered only eight days before the report, on 20 July 2026, through Key-Systems GmbH. The authoritative name servers are olga.ns.cloudflare.com and sonny.ns.cloudflare.com, indicating that the domain is hosted on Cloudflare’s network. DNS resolution points to IP address 172.67.147.162, a Cloudflare edge node that is commonly used by both legitimate and malicious actors to hide origin infrastructure. Two of ninety‑one security vendors on VirusTotal have flagged the domain, and the site is currently listed on two public blocklists.
Independent anti‑phishing feeds PhishDestroy and ScamSniffer also block sinport.org, confirming that the domain is recognized as a phishing vector. No additional intelligence such as SSL certificate details, HTTP response codes, or page title has been published, so the exact content and targeted brand remain unverified. The limited telemetry indicates a high‑risk profile: recent creation, use of a reputable CDN, and early detection by multiple vendors suggest a purposeful campaign.
However, the lack of publicly available page metadata prevents attribution to a specific brand or lure type. Defenders should add sinport.org to outbound filtering and DNS sinkhole rules, monitor for connections to 172.67.147.162, and enforce credential‑validation controls for users who may be exposed to credential‑stealing pages. Continuous re‑inspection of the domain through sandbox or URL‑reputation services is advised to capture any evolving payloads or page changes.