UltaHost Incident Database
Every documented incident in the UltaHost record, newest first — each entry dated, categorized, and linked to its sources. Link directly to any incident with its anchor.
Last updated: · 25 rated critical · For the chronological narrative, see the timeline.
UltaHostAbuse.com publishes Round 10 “The Paper Trail”
Round 10 covers four things: a US federal copyright injunction that names UltaHost as the registrar for a piracy service; PhishDestroy's count of 1,134 phishing domains registered through the company, spot-verified against the registry; a screening of the named owners against sanctions, securities and court records that found nothing; and a correction to Round 9, which understated the abuse reporting against the network by checking eight addresses instead of all 85 prefixes.
It also re-checks what was already published. The scam domain from Round 9 is still serving on day 20. ICANN has taken no further action since the March cure. The broken-HTTPS rate moved the wrong way, from 12 of 32 sampled customer sites to 14.
Owner screening: nothing found on sanctions, securities or enforcement records
This site has stated in several places that no personal legal actions or criminal allegations have been found against the founders individually. Until now that was an assertion resting on our not having looked anywhere in particular. We looked in named places, on a stated date, so the negative can be cited rather than trusted.
Screened terms: Doughouz, Doughous, Elin Doughouz, Elin Doughous, Elin Ander Doughouz, Deen Doughouz, Younes Doughouz, plus Ultahost, ScriptSun, WoWonder, Wolvor, Doughouz Group, PixelPhoto and DeepSound. Searching a single spelling is how a screening exercise produces a false clean — ICANN addressed its breach notice to “Doughous” while Companies House and Crunchbase say “Doughouz”, so both were run.
- ● OFAC SDN list (US Treasury, 19,250 rows retrieved) — no match
- ● OFAC consolidated list — no match
- ● UK OFSI consolidated list (19,763 rows retrieved) — no match
- ● SEC EDGAR full-text search — no match on the 14 terms that answered; one of 15 returned a server error and is recorded as not checked
- ● CourtListener, widened to first-name and entity-brand shapes — no match on any individual; one of 24 queries was rate-limited and is recorded as not checked
Two things the widened court sweep did surface, both reported here so nobody presents them as findings they are not. A full-text docket search on the surname returns five results and we attribute none of them: three are bankruptcy filings bearing the surname, of which two were filed in 1996 and 2002 when a person born in January 1992 was four and ten years old and the third shares only a surname, while the other two are unrelated filings — a criminal prosecution and the Tribune Media bankruptcy — where the string merely appears in the document. And the entity sweep found the copyright injunction described above — which names the company as a third-party registrar, not any individual.
What a negative here does and does not mean. Sanctions lists name sanctioned persons and EDGAR covers US securities filings; a privately held hosting business would not normally appear in either, so absence is expected rather than exonerating. It rules out one specific category of allegation and nothing more. Where a source could not be retrieved we record it as not checked, never as clean.
Correction: we understated the abuse reporting against UltaHost's network
Round 9 reported, under the heading of findings that cut against us, that the eight IP addresses in that investigation carried AbuseIPDB confidence scores between 0% and 33% and that this was “not the profile of an address range the internet has collectively condemned”. That was accurate about those eight addresses and wrong as a statement about the network, because eight addresses chosen for a different purpose are not a sample of 22,000.
Checking every one of the 85 announced /24 prefixes gives a different picture:
- ● 68 of 85 prefixes contain at least one reported address
- ● 191 reported addresses in a 30-day window
- ● 20 addresses at confidence 75% or higher, of which 14 sit at 100%
- ● The worst, 192.142.37.70, carries 275 reports at 100% confidence; 84.200.24.229 carries 229; 159.100.19.157 carries 116
Several of the worst addresses sit in the ranges Round 9 traced to other registries: 192.142.37.70 and 192.142.53.10 are in the AFRINIC space administered from a Gmail address, and 202.155.11.65 (confidence 97) is in the block leased through the IPXO marketplace.
Why we are flagging our own error rather than quietly restating the number. The original figure was published prominently because it was inconvenient for this site, and a correction that runs the other way has to be published just as prominently or the first one was theatre. The methodological lesson is the ordinary one: a sample selected to answer one question is not a sample for a different question. AbuseIPDB scoring is also conservative, so a low score on any single address still is not exoneration — in either direction.
1,134 phishing domains registered through UltaHost, 698 of them still live
Round 9 established that UltaHost was both registrar and host for one scam domain, sampled 9 of 24 domains as registered through it, and said the pattern probably ran wider. It does. PhishDestroy tracks abuse by registrar of record, and its Ultahost page reports:
- ● 1,134 phishing domains registered through Ultahost, Inc.
- ● 698 still alive, 436 taken down — a 61.6% alive rate
- ● 98.5% flagged by VirusTotal; 800 domains at a VirusTotal score of 5 or more
- ● Coverage begins 23 July 2025 — so this is roughly thirteen months of registrations
- ● Registrar risk score 68/100, ranked 3rd worst, against 33,427 domains under the registrar in total
PhishDestroy's own conclusion, in its own words: “62% of these reported domains remain active, suggesting inadequate enforcement of abuse policies.”
We did not take the attribution on trust. Five domains from that list were checked independently against Verisign's authoritative .com registry, and all five return Ultahost, Inc., IANA 4331 as registrar of record: coinmarketcaa.com (a CoinMarketCap typosquat), safeurl-leedger.com and ledger-bank.com (Ledger), coinbasepromotionclaims.com and ultrexcapitalfx.com. As a control we ran the same check on coinbase.com, which correctly returns MarkMonitor — so the check distinguishes registrars rather than agreeing with whatever we ask it.
The caveat on the trend. This site previously published 871 flagged and 374 alive (42.9%) as of 19 July. The flagged count is up 263 and the alive rate is up nearly 19 points, but part of that rise is a cohort effect: domains added recently have had less time to be taken down, which lifts the alive rate without anything changing about enforcement. The claim we stand behind is the raw count and PhishDestroy's own characterisation — not “enforcement got worse”.
We tested whether UltaHost is slow. It is not.
Slowness is one of the most common complaints made about any budget host, and it is frequently asserted about this one. We measured it rather than repeating it.
From three independent vantage points we recorded 296 samples across 37 hosts, reporting server processing time — the interval after the TLS handshake completes and before the first byte of the response arrives. That deliberately excludes DNS, TCP and TLS setup, so the figure reflects the server rather than the distance to it. Against Google's published guidance (under 800ms good, over 1800ms poor):
- ● Median: 12ms
- ● 36 of 37 hosts in the “good” band
- ● Zero in the “poor” band; the slowest was 1,507ms
UltaHost's shared hosting is fast. Whatever is wrong with this company, raw server response time is not it, and we will not claim otherwise.
How this nearly went wrong, which is worth stating. 106 of the 296 samples returned HTTP 000, and our first aggregation treated that as a valid status — scoring eleven unreachable sites as “0ms, good”. They were not fast; they were not answering at all. Chasing that error is what produced the certificate findings above. Two of the three vantage points are in the same German datacentre, so this is enough to show a figure is not one network's artefact and not enough to describe global performance.
38% of sampled customer sites fail HTTPS — several serve another tenant's certificate
We sampled 32 sites sharing UltaHost's four managed cPanel servers and inspected the certificate each one actually presents. Twelve fail in a browser:
- ● 1 expired certificate — 007truckingcorp.com, expired 26 May 2026, still expired 86 days later
- ● 3 self-signed certificates, all issued by globaloffshoremargin.com — one tenant's self-signed certificate being served to three unrelated sites
- ● 6 serving a certificate for the wrong domain entirely
- ● 2 domains dead, resolving nowhere
The wrong-certificate cases are the telling ones. 01kexchange.com, ai-findsignals.com and odmastery.academy — three unrelated businesses — each present a certificate issued for cpcontacts.webadormyappiiclohelverydssxc.com. 1000-fragen.ch and echallan-parivahan.com both present one for fasttransitlogistic.com, another customer's domain. quaterbit.ae presents the server's own hostname, lax007.arandomserver.com.
This is a platform failure rather than customer error. cPanel — the control panel UltaHost sells with these plans — includes AutoSSL, which issues and renews certificates automatically and at no cost. Every visitor to these sites gets a full-page browser security warning.
Method and limits. 32 sites, chosen by stepping evenly through the reverse-DNS list for each of the four IPs rather than taking the first alphabetically, with flagged, gambling and adult domains excluded. Each certificate was inspected directly and the classification re-confirmed independently with openssl. A sample of 32 supports the proportion loosely, not to the percentage point, and a certificate can be fixed the day after we looked.
A Turkish UltaHost company appears in the address registry, named nowhere else
UltaHost's terms of service name four jurisdictions: Dubai, Istanbul, the UK and the USA. Round 8 examined the UK arm and found it dormant. The Istanbul arm has now surfaced in a registry, with a legal name:
ULTAHOST HOSTING VE VERI MERKEZI LTD. ŞTI.
RIPE organisation ORG-UHVV1-RIPE · Yakuplu Mah., Hürriyet Blv., Skyport Residence, Beylikdüzü, Istanbul · holder of 5 announced prefixes
Ltd. Şti. is the Turkish limited-company form, so this is a distinct legal entity from both UltaHost Inc (Delaware) and the dormant ULTAHOST LTD (UK). Alongside it, RIPE holds two separate organisation objects for the Delaware company — ORG-UI47-RIPE (“UltaHost Inc”, 47 prefixes) and ORG-UI46-RIPE (“Ultahost, Inc.”, 3 prefixes) — at the same Middletown address. A further 8 prefixes are registered to an entity recorded only as “Private Customer” at “Private Residence”, one of them carrying the netname UA-WICOM-RENT25.
Reading this fairly. Operating companies in several countries is normal for a hosting business, and duplicate registry objects are often just administrative untidiness rather than design. We could not find the Turkish company in any free, English searchable register to confirm its officers, and we do not claim it is concealed — only that a fourth corporate identity exists, that it holds real infrastructure, and that it was discoverable solely from the address registry rather than from anything the company publishes.
The scam-hosting IPs are African address space administered from a Gmail account
Resolving all 86 prefixes UltaHost announces to the registry that actually governs each one produces a map of the company that no marketing page shows. Seventeen are not administered by RIPE at all. Of those:
- ● 13 are AFRINIC space — the African registry — held by an entity called “Ultahost RR” and registered to the Netherlands and Spain. They sit beneath a /16 that AFRINIC allocated to a South African company, X-DSL Networking Solutions.
- ● 1 is leased through IPXO, a commercial IP-address rental marketplace.
- ● 3 belong to Cogent, an upstream carrier — ordinary and unremarkable.
Two of those African blocks are the ones this investigation keeps returning to: 192.142.10.0/24, the cPanel server carrying the scam cluster, and 192.142.18.0/24, the range whose address served Cobalt Strike and Brute Ratel C4 command-and-control.
The registered administrative and technical contact for that address space, in AFRINIC's public database, is ultahost@gmail.com — a free webmail account.
Set that beside what this site has documented since Round 2: a reporter who tried to report a fraudulent site was turned away for using a Gmail address. The company that would not accept an abuse report from Gmail lists a Gmail address as the contact of record for the very address space the abuse is running on.
What this is not. Using address space from another region is legal and ordinary — the IPv4 transfer and lease market exists precisely for this. Netrouting, LayerSwitch, firstcolo and Pentech appear in these records as upstream carriers and sponsoring registries, not as UltaHost entities, and we are not suggesting otherwise. The finding is narrower: the infrastructure carrying the abuse is held at one remove from the operating company, in a registry on another continent, behind a free email account.
197 flagged domains on four UltaHost shared servers, and the rate is rising
Round 8 reported 20 scam domains on UltaHost's cPanel control plane, found by filtering scans whose reverse DNS had been captured. Querying the four cPanel IP addresses directly returns far more:
- ● 536 distinct domains seen across the four servers
- ● 197 carry a phishing / malware / scam / fraud classification
- ● 118 of those sit on one address, 79.133.41.61
- ● By month first seen: 11 in June, 118 in July, 60 in the first 20 days of August
The classifications are not ours. They are the tags urlscan.io records from its own analysis and from contributors including PhishReport and PhishDestroy: 35 domains tagged 419 scam / advance-fee fraud, 28 cryptoscam, 16 phishing, and 91 serving an open directory. Recurring campaigns are visible rather than isolated registrations — a Ledger hardware-wallet firmware phishing set including the typosquat leedger-firmware-update.com, a three-domain two-factor-authentication kit (securebo-, onlinebo- and verifybo-2fauser.com), and government impersonation aimed at three countries: irsgovtax.xyz, echallan-parivahan.com (India's traffic-fine portal) and dubaichamberpay.com.
Limits. A urlscan tag is a scanner's classification, not an adjudication, and a rising count partly reflects rising scanning. The date is the date a domain was first scanned, not the date it appeared — so the monthly figures show when the outside world noticed, which is a floor on when it existed. What the numbers do establish is that this is continuing now, five months after ICANN recorded the registrar breach as cured on 23 March 2026.
UltaHost registered a scam domain, hosts it, and it is still serving
Every previous round could be answered with “we only host it, we cannot police every customer.” This one cannot. On the same domain UltaHost is both the registrar of record and the hosting provider, and the content is a direct impersonation of a real financial-media brand.
- ● Registrar: Ultahost, Inc., IANA ID 4331 — read from Verisign's authoritative .com registry, not a third-party database
- ● Registered:
- ● Hosted on: 192.142.10.5, whose reverse DNS is cp11.ams1.ultacp.com — UltaHost's own managed cPanel plane
- ● Status on : HTTP 200, 184 KB, serving
The page is not merely themed after FX Empire. It carries the byline “By : FXEmpire”, a cloned author biography, and FX Empire's own legal disclaimer copied verbatim — the brand name appears over 200 times — while promoting a cryptocurrency presale called SPX40K.
Three sibling domains registered through UltaHost tell the other half of the story, and we report it because it is the fairer picture: gro24h-cointelegraph.com and gro24h-cryptoslate.com (both registered 26 June) now carry the registry status client hold and no longer resolve, and spxpresale-cryptoslate.com redirects to cPanel's “Account Suspended” page. UltaHost does act. Which is precisely why the one still serving matters: it is not that they cannot suspend a domain, it is that this one has been up for sixteen days against a policy promising that financial scams are “immediately disabled without prior notice”.
Limits. We are describing a registration record, a DNS record and a page we retrieved and stored. We are not asserting UltaHost knew about this domain, nor that anyone there reviewed it. VirusTotal currently shows 2 vendors marking it suspicious and none malicious, so the brand impersonation — which is plain on the face of the page — is the stronger evidence here, not the vendor score.
UltaHostAbuse.com publishes Round 9 “Registrar and Host”
Round 9 reports a domain where UltaHost occupies every role at once — it sold the name, it serves the page, and its own policy promises that pages like it are disabled immediately. Around it: 197 flagged domains across four shared servers with the monthly count rising, African address space administered through a free Gmail account, a fourth corporate identity found only in a routing registry, and 38% of sampled customer sites failing HTTPS.
Three checks came back against the site's own expectations and are published as prominently as the rest: UltaHost's shared hosting is fast, Google Safe Browsing blocks none of these domains, and AbuseIPDB barely registers the IP addresses.
A customer says the DMCA-ignored product was not DMCA-ignored
“They said it's dmca ignored before buying but after it turned out that it's not!!! THEY SUSPEND YOU WEBSITE WITHOUT YOUR NOTICE!!! ABSOLUTE SCAAAM” — 1★, Trustpilot, 15 Aug 2026
Round 8 established from UltaHost's own website that it sells “Fast and Reliable Offshore DMCA Ignored VPS Hosting” as a named product, promising customers they can “avoid copyright issues”. This is the other end of that transaction.
Limits, and they matter here. This is one customer's account and we cannot verify it: we have no access to their account, their ticket history, or whatever was hosted. It is entirely possible the content breached some other term of service, in which case suspension would be proper. We publish it because it is dated, specific, and lines up with a marketing claim we verified independently from the company's own pages — not because we can confirm what happened.
UltaHostAbuse.com publishes Round 8 “The Business Model”
Round 8 is the first round built almost entirely from primary records rather than from customer reports: ICANN's own compliance index and monthly registrar transaction files, UK Companies House filings, RIPE registry and routing data, abuse.ch URLhaus and ThreatFox, urlscan.io, the free court record, and UltaHost's own website.
It was published the same day as a self-audit that retracted several claims previously made on this site, including one that could not be supported at all. Those retractions are listed in the changelog entry for Aug 8, 2026 and are not hidden: a report about a company that makes claims it cannot support has no standing unless it holds itself to the same test.
No litigation against UltaHost in the free public record
We searched the free court record and found nothing, and we are reporting that with the same prominence we would have given a hit. Sixteen queries across CourtListener v4 — “Ultahost”, “Ultahost, Inc”, “ScriptSun”, “WoWonder”, “Doughous” — against opinions, dockets and full document text returned zero. The UK's Find Case Law archive returned zero for ultahost, Doughouz and Doughous. Companies House shows no insolvency and no strike-off action.
Why this is “nothing found” and not “nothing exists”. RECAP contains only those federal dockets somebody has already paid to retrieve, so it is a large sample of US federal litigation, not a complete one. BAILII blocks automated retrieval and we did not check it. Neither Turkey nor the UAE — where the principals are based — publishes a free, name-searchable judgment database. A dispute settled privately or filed in a state court leaves no trace in any of these. So: we found no litigation, and that is all we found.
A same-surname warning. Searching “Doughouz” in dockets returns five US bankruptcy filings. We attribute none of them. Two were filed in 1996 and 2002, when a person born in January 1992 was four and ten years old. A third, filed in 2025, shares only a surname with no established connection. We mention them purely so that nobody else presents them as findings about this company.
The UK company has filed dormant accounts three years running
A dormant company, in UK company law, is one that has had no significant accounting transactions in the financial year. ULTAHOST LTD has filed dormant accounts three times in a row:
- ● Period ended 31 January 2024 — filed 23 Sep 2024
- ● Period ended 31 January 2025 — filed 9 Mar 2026
- ● Period ended 31 January 2026 — filed 7 Apr 2026
Meanwhile UltaHost's own terms of service extend the agreement across “UltaHost Dubai, UltaHost Istanbul, UltaHost Ltd UK, and UltaHost Inc USA”. The UK entity is presented to customers as an operating arm and declared to the registrar of companies as dormant.
The rest of the filing, read directly:
- ● Sole director and company secretary — the same person, held as two separate officer records
- ● 75–100% of shares, voting rights and the right to appoint and remove directors
- ● Turkish nationality, resident in Turkey; date of birth recorded as January 1992
- ● Identity verified under the Economic Crime and Corporate Transparency Act on 21 Nov 2025
- ● Zero other UK appointments for either officer record
- ● No insolvency history, no charges, and filings are up to date — this is a compliant dormant company, not a delinquent one
An inference we refuse. The registered office, 71-75 Shelton Street, is the best-known mass mail-forwarding address in the UK, shared by tens of thousands of unrelated companies. “N companies at the same address” is therefore worthless as evidence and we do not make that argument. The only valid structural test is officer-sharing — whether this director appears on other companies — and it returns nothing. There is likewise no UK-registered ScriptSun, WoWonder, Wolvor or Doughouz company. If there is a wider corporate group, it is not visible on the UK register.
ICANN's own files show the registrar deleting domains in bulk from Feb 2026
ICANN publishes a monthly transaction report for every accredited registrar. Filtering 19 months of the .com reports to IANA ID 4331 gives a growth curve and a deletion curve, both from ICANN's own files:
- ● .com under management: 0 (Oct 2024) → 3,985 → 9,437 → 16,308 → 21,038 → 23,669 → 25,179 (Apr 2026)
- ● Deletions without the redemption grace period: never above 236 in any month across the first 15 reported months (zero in 11 of them), then 332 (Jan 2026), 1,399 (Feb), 1,283 (Mar), 1,032 (Apr) — 4,327 cumulative
The distinction matters. A normal expiry passes through a redemption grace period. A no-grace deletion skips it, which is characteristic of a registrar-initiated removal — the mechanism a registrar uses when it takes a domain down itself.
What we are not claiming. We are placing two dated series side by side and leaving the inference to the reader. The deletions begin in the same window as the final stretch of the ICANN cure process, which ended 23 March 2026 — but ICANN's files do not state a reason for any deletion, and bulk removals are equally consistent with clearing out a spam registration wave, a payment-fraud chargeback batch, or a policy change. We do not assert causation, and nobody should read one into the dates alone.
Every domain on one UltaHost IP is a gambling site — which its own terms prohibit
UltaHost's terms of service prohibit using its services to “Promote gambling, casinos, gaming, sports betting, daily fantasy sports, lottery or chain letters regardless of content or origin and regardless of your citizenship or the legality of such activities within your country”.
A reverse-IP lookup on 84.200.154.40 returns 290 hostnames. Deduplicated to registrable domains — shared cPanel hosting creates several hostnames per site — that is 120 distinct domains, and every single one carries a gambling marker: 28 are explicit (bo999slot.com, maxbet111.com, uranus4d.net — “4D” being the Indonesian lottery format) and the remaining 92 follow the Indonesian slot-brand naming convention (angka169.com, hoki818.com, dewa268.com). The residual, after classification, is zero.
On , that same IP served AgentTesla credential-stealing malware from lion44.net/wp-includes/theme-compat/… — a compromised WordPress installation on one of those gambling sites, per abuse.ch URLhaus.
Gambling domains also sit on the managed cPanel plane itself: 1xbet-ir.app and 1xbet-iran.app, zigzagbonus.bet, pinupcasinorussia.click, and three ganobet variants.
Limits. This shows what shares an address, not who owns the content, and we make no claim that UltaHost knows. Our classifier is published in the repository and its residual is printed so the count can be checked rather than taken on trust — our first pass undercounted, missing bo999slot and the 4D convention entirely, and we corrected it. The reverse-IP service caps at 500 hostnames, so counts at exactly 500 elsewhere are floors, not totals. The claim here is narrow: content UltaHost's own terms prohibit is running on UltaHost's own shared hosting, at scale.
Ransomware-operator tooling runs on UltaHost's own network
We read three public threat-intelligence datasets directly, filtered to UltaHost's own autonomous system AS214036:
- ● abuse.ch URLhaus: 998 malware-distribution URLs, Feb 18, 2022 – Aug 5, 2026, five still serving at the time of reading
- ● abuse.ch ThreatFox: 9 command-and-control servers, every one at 100% confidence — XWorm (×2), Sliver (×2), Bashlite, AsyncRAT, Brute Ratel C4, Havoc, Cobalt Strike
- ● urlscan.io: 2,110 submissions tagged phishing resolved inside AS214036
The C2 list is the part that matters most, and it is a qualitatively different finding from phishing volume. Cobalt Strike, Sliver, Brute Ratel C4 and Havoc are post-exploitation frameworks: the tooling an intruder uses after getting inside a network, and the standard kit of ransomware crews. One address, 192.142.18.214, appears twice — carrying two different commercial-grade frameworks ten months apart.
Limits, stated plainly. Most of the 998 URLs are IoT-botnet noise (Mirai/Gafgyt families); only 54 carry Windows-crimeware tags. Volume peaked in 2025 (528 URLs) and is lower in 2026 (79) — we are not claiming an acceleration, and the honest reading is that URLhaus activity has declined. urlscan's unfiltered total for the ASN is reported as at least 10,000 because 10,000 is urlscan's anonymous result cap, not a count. And a host is not automatically culpable for what a customer runs: the question a registrar's own abuse policy invites is how long it stays up.
Two Reddit threads track the same multi-day outage on the Frankfurt cPanel server
Two threads posted within about a fortnight of this report, in different subreddits, describe the same incident. One is titled “UltaHost Outage 8/6 to…”:
“Is anyone aware what’s going on with UltaHost? It’s day 2 of an outage with no new updates and now I can[’t] get into their Control Panel”
“I came to Reddit to see if anyone else had info. because I wasn’t getting any from Ultahost.”
A commenter links UltaHost's own status page, which names the machine and its address: “the shared hosting server CP3 (79.133.41.61) in Frankfurt… there is no confirmed ETA… We expect the maintenance to be [f]ully resolved within the next 24 hours.” It was marked resolved roughly three days later.
79.133.41.61 is the server this round found carrying 118 flagged domains — more than the other three cPanel boxes put together. The customers waiting out this outage were sharing a machine with the largest concentration of flagged scam domains found anywhere in UltaHost's estate. That link exists only because UltaHost published the IP address itself.
Balance. Reddit is not uniformly hostile to this company and we are not going to pretend it is. The same search returned a customer who migrated from Hostinger and reported “more stability”, and two others reporting months of trouble-free use. The volume is low either way; what is notable is that the negative reports cluster on outages and on support going quiet, which are the two things independent measurement can corroborate.
The Frankfurt migration outage, confirmed by three independent sources
Three sources that do not talk to each other describe the same incident in the same week.
- ● UltaHost's own status page: work on “the shared hosting server CP3 (79.133.41.61) in Frankfurt… there is no confirmed ETA… We expect the maintenance to be [f]ully resolved within the next 24 hours”. Marked resolved roughly three days later.
- ● Reddit, two separate threads: “It's day 2 of an outage with no new updates and now I can['t] get into their Control Panel”.
- ● Trustpilot, 2★ on 8 Aug: “currently my 2 websites are down (and have been for a 3 days) and they only thing they say is that they are sorry but they are doing upgrade at Frankfurt (???????) location. no warning, no notice before doing anything. avoid”.
Around it, a run of Trustpilot reviews on the same theme within four days — “Run away from this company, their migration takes forever” (1★, 8 Aug), “They migrate server once every month so you have a downtime for days” (1★, 7 Aug), “a lot of down time in same month” (1★, 7 Aug).
79.133.41.61 is the server carrying 118 flagged domains — more than the other three cPanel boxes combined. Paying customers were offline for days on the same machine, and that connection is only possible because UltaHost published the IP address on its own status page.
Fairly stated: planned migration work is legitimate and every host does it. What the three accounts agree on is narrower — that it ran well past the stated 24 hours, and that customers say they were given no advance notice.
Scam sites are running on UltaHost's own managed cPanel hosting
Sharing an autonomous system proves very little — a big network has many customers. The reverse-DNS record is the stronger signal, and it points somewhere more specific: these domains resolve to hostnames like cp11.ams1.ultacp.com and cp5.fra1.ultacp.com — UltaHost's own managed cPanel shared-hosting plane, not merely its address space.
Of 78 urlscan submissions on that plane, 20 distinct domains, several scanned on :
- ● A crypto-presale cluster impersonating financial media: spx40k-fxempire.com, spxpresale-cryptoslate.com, gro24h-cointelegraph.com, gro24h-cryptoslate.com — all on one IP
- ● Fake banks: theroyalbankgroup.com, stridesglobalbk.online (both tagged advance-fee fraud / phishing)
- ● Fake pharmacy/chemical suppliers: labchems.org, usalabchems.com
- ● Brand-impersonation lookalikes on the same plane: three Adobe variants (adobeviewer.com, adobe-docviewer.com, adob-viewer.com) plus aliexpressboost.com
This bears directly on UltaHost's own abuse policy, which promises that domains involved in “phishing attempts… or financial scams” are “immediately disabled without prior notice”. And it bears on the reply a customer received on LinkedIn, already documented on this site, that UltaHost does not investigate abuse without a trademark complaint or court order — the Adobe and AliExpress lookalikes are exactly the trademark case that reply invites.
Limits. A urlscan tag is a scanner's classification, not an adjudication. We report what the scans and the PTR records say, not what UltaHost knew or when. Several of these were scanned within days of our reading, so we cannot say how long they had been up.
UltaHost sells “DMCA Ignored” hosting while promising ICANN it polices abuse
Both of these pages were live on UltaHost's own website on . Neither is an allegation, an inference, or a third-party characterisation — they are the company's own marketing copy and its own published policy, quoted verbatim.
ultahost.com/dmca-ignored-vps
“Fast and Reliable Offshore DMCA Ignored VPS Hosting. Protect your data privacy and avoid copyright issues with UltaHost's DMCA Ignored VPS. Enjoy secure, confidential hosting with optimal speed and unlimited bandwidth.”
ultahost.com/abuse-handling-policy
“As an ICANN-accredited registrar, UltaHost strictly adheres to Section 3.18 of the Registrar Accreditation Agreement (RAA), which mandates the timely handling of abuse reports…”
“For cases involving confirmed malicious intent (such as phishing attempts, malware distribution, financial scams, or child exploitation content), the domain will be immediately disabled without prior notice.”
What this does and does not show. Offering DMCA-ignored hosting is not illegal, and a registrar's abuse obligations under RAA §3.18 are not the same duty as a host's response to a copyright notice — the two pages are not a contradiction in the strict legal sense. What they do establish is the company's own positioning: it markets the avoidance of copyright enforcement as a product feature while citing its ICANN accreditation as evidence that it polices abuse. Both claims are UltaHost's own words, which is the strongest available evidence of what a company advertises.
UltaHostAbuse.com publishes Round 7 "The Reputation Machine"
Round 7 turns from what UltaHost's customers say to what UltaHost itself says, using two public datasets: Meta's Ad Library and Trustpilot. It documents the 4.9 rating claim running in 101 paid ads against a measured TrustScore of 3.6, three simultaneous and mutually inconsistent uptime figures including 100% claimed during a documented outage, and the invited-versus-organic review split that explains how the headline average is produced. It also reports one allegation we tested and could not substantiate.
Comments on UltaHost's Facebook ads cannot be audited by any third party
Recording a structural limit rather than a finding, so that neither our silence nor our numbers get read as a verdict.
- ● Ad comments are not publicly retrievable. All 166 ads are “dark posts” created in Meta's ad tools: none references an existing page post, and Meta's Ad Library exposes ad creative without ad engagement — there is no comment field in its published API.
- ● They still exist, just not for us. A dark post collects comments, and they are visible to the people the ad is served to. They cannot be pulled from the Ad Library, from an archive, or by us. Anyone shown one of these ads can see more than we can.
- ● Separately, the page timeline is public. 150 posts spanning March 1, 2025 – July 31, 2026 carry 37 comments from 16 distinct accounts, with no identical text under different accounts, and skewing negative at 11 complaints to 8 positive remarks.
Those timeline figures describe the timeline. They are not evidence about the advertising, which is a separate and closed surface, and we draw no inference from one to the other. On the question of whether these ads carry purchased comments we take no position, because from outside Meta the question cannot be settled either way.
Invited reviewers rate UltaHost 4–5★; walk-in reviewers rate it 1–2★
Trustpilot records how each review arrived. Splitting the 200 most recent reviews for ultahost.com by arrival channel shows two populations describing opposite experiences:
- ● Company-invited (135 reviews, Trustpilot's automated invitation flow): 95 rated 4–5★ — 70%
- ● Organic walk-ins (58 reviews, reviewer arrived unprompted): 54 rated 1–2★ — 93%
- ● Only 8 of 200 reviews sat at exactly 3★ — a 4% middle
- ● 69% of reviewers had written exactly one lifetime review; among 5★ reviewers, 73%
- ● Every one of the 200 reviews in this sample carried a company reply, at every star level. Trustpilot's own profile counter independently states “Replied to 100% of negative reviews” (read Aug 21, 2026), so the figure is the platform's, not just ours — though the same counter now says the company “typically replies within 2 weeks”, where it previously said one
This is the mechanism behind the reputation gap Round 6 identified, and it is worth stating precisely what it is and is not. We found no evidence of fabricated review text: across 200 reviews only one duplicated body of text appeared under more than one author. Soliciting reviews is permitted on Trustpilot and is not misconduct. What the data shows is that UltaHost's public average is shaped by which customers are invited to speak, and that customers who arrive of their own accord report a very different product.
UltaHost is named in a US federal copyright injunction as the registrar for a piracy service
Round 8 searched the free court record for litigation touching this company and found none, and this site retracted an earlier claim that UltaHost was “stonewalling actual lawsuits”. That search missed something for a mundane reason: it queried "Ultahost, Inc" with the comma. Without it, one federal case appears.
TelevisaUnivision, Inc. and Televisa, S. de R.L. de C.V. v. Luis Fermín Gil Alphand, et al.
US District Court, Southern District of Florida · 1:26-cv-23911-KMW · filed 4 June 2026 · nature of suit 820 Copyright · cause 17 U.S.C. §504 · preliminary injunction entered 24 July 2026
The injunction covers four pirate IPTV services — Roja Directa, Tarjeta Roja, PirloTV and XuperTV — and carries a schedule of the intermediaries that serve them. Entry 81 reads: “Ultahost, Inc. — Domain registrar (Roja Directa)”. The operative clause orders that “at Plaintiffs' election, any domain name registrars or registries or others with access or control of said domain names are hereby ordered to delete, cancel, disable, and/or transfer to Plaintiffs any such domain names”.
What this is not, and it matters. UltaHost is not a defendant. Well over a hundred other intermediaries sit on the same schedule (entries 22 to 137), including GoDaddy, Akamai, Squarespace Domains, eNom, EuroDNS, Sav.com, LeaseWeb, Newfold Digital, Vercel, Automattic, Canva and the RIPE Network Coordination Centre. Nobody supposes Canva or a regional internet registry is running a piracy operation: appearing in a schedule like this is routine in anti-piracy litigation and is not, by itself, evidence of wrongdoing by any company on it.
The plaintiffs did distinguish between the two kinds of intermediary, which is the genuinely useful detail here. Four companies were originally named as defendants and later voluntarily dismissed — Enzu LLC, Dash Networks Inc., Digital Ocean LLC and HostGator LLC. UltaHost was never in that group; it appears only in the schedule of third parties. We also cannot say whether UltaHost complied: the order acts only at the plaintiffs' election, and we do not know what was elected.
What is fairly reportable is the juxtaposition. A company that sells “Offshore DMCA Ignored VPS Hosting” as a named product, promising customers they can “avoid copyright issues”, now appears in a US federal copyright injunction as the registrar of record for a long-running piracy brand. That is the first time this investigation has found the company in any federal court document at all.
UltaHostAbuse.com publishes Round 6 "The 2026 Meltdown"
Round 6 documents the June 2026 meltdown: the multi-day outage timeline recorded by independent status trackers, storage-node data loss, the cross-platform reputation gap (Trustpilot 3.4 vs 4.9 on business-review platforms), regional performance benchmarks, and the refund-policy fine print that excludes nearly everything.
Istanbul storage-node failure becomes an 11+ day multi-node outage — still unresolved
Third-party status trackers (StatusGator, EntireWeb, SaaSHub) record repeated “Istanbul Storage Node Degradation” incidents from June 22 onward — UltaHost attributes the extended downtime to failed disks on a storage node and a slow data-rebuild, with concurrent warnings on Amsterdam and Toronto. First logged as a June 22–29 window, the incident continues through July 2–3, making it an 11+ day storage failure: StatusGator flags the Amsterdam and Istanbul nodes as Down and Toronto as degraded — an active, multi-node major outage against the marketed “99.9% uptime guarantee” and the 43.78% uptime measured by WebsitePlanet. In the same window, the BBB letter grade ticks from D to D+ (still not accredited; 6 complaints, failure to respond to ≥1).
Scamalytics quantifies UltaHost fraud risk: 37/100 medium-risk ISP
Scamalytics rates UltaHost a 37/100 medium fraud-risk ISP — approximately 37% of observed UltaHost traffic flagged as potentially fraudulent across 24,512 tracked IP addresses — the first quantified third-party fraud-scoring signal. The same update documents the casino-hosting own-contradiction (HostAdvice's “Best Online Casino Hosting Providers” list features UltaHost while UltaHost's own ToS prohibits promoting gambling) and the asymmetric enforcement pattern: paying customers' servers suspended without notice on unsubstantiated phishing allegations, while abuse reports against actual bad actors are met with demands for a trademark certificate or court order.
Named phishing campaign attributed: ~50 Ultahost-registered domains targeting Meta/WhatsApp/Instagram
Published IOCs attribute a coordinated Meta/WhatsApp/Instagram fake-job phishing operation (late 2024 — March 2025) to ~50 Ultahost-registered domains — one shared C&C domain (spyder1279.blog), one shared hosting IP, and WebSocket-based 2FA/OTP interception. The same week, WebsitePlanet's 2026 review ranks UltaHost #3752 of 3,860 hosts (bottom 3%) with 43.78% measured uptime and 17 consecutive days down, and a Web Hosting Talk thread documents UltaHost sending legal threats to a customer who won a credit-card chargeback.
Trustpilot rating drops to 3.4/5 "Average" — paid-review machine overwhelmed
The headline Trustpilot rating on ultahost.com drops to 3.4/5 “Average” (previously the Excellent tier) — 1,737 reviews on ultahost.com and 2,570 combined across both profiles of the dual-profile structure with ultahost.io, whose review base shows a bimodal pattern (57% five-star + 29% one-star, gap in the middle). Cybernews mainstream press now cites the April 11 forced-reboot case.
[SUPERSEDED — updated Aug 8, 2026] The 2,570 combined figure is withdrawn. It depended on the ultahost.io profile, which did not resolve on Aug 4, 2026. The ultahost.com reading in this entry stands as a dated May 2026 measurement; the .com profile has since moved to 1,750 reviews at 3.5/5.
macOS server billed immediately, delivered unusable, refund refused
A comment on UltaHost's own Facebook page dated states the customer “purchased a macOS server from Ultahost”, that UltaHost “charged my payment immediately, but the service was not delivered in a usable working state”, and that rather than fixing or refunding, “they keep repeating policy language and asking me to wait.”
A separate Trustpilot review dated , from a different country, is titled “False Refund Policy + Unusable macOS VPS – Terrible Service & Unfair Terms”. Two independent platforms, ten weeks apart, same product and same failure mode — which is why this entry is marked verified rather than corroborated.
It sits alongside other 1★ accounts from the same window: a domain described as “abducted for no clear reason” (June 26, 2026) and a UK customer arguing UltaHost refused a statutory refund despite its own terms placing its UK entity under UK law (July 31, 2026). Of the 200 most recent Trustpilot reviews, 16 negative reviews concern refunds or billing.
UltaHostAbuse.com publishes Round 5 "Money Trail" investigation
Round 5 documents the financial mechanism sustaining UltaHost: 70% affiliate commissions (industry standard 20-40%) paid in cryptocurrency; an Envato/CodeCanyon backdoor pipeline run by the same Doughouz family; a refund policy that pre-classifies chargebacks as “criminal fraud”; and HostAdvice openly listing UltaHost as a top Telegram Hosting service used by carding, wallet drainers, and pig-butchering ring management.
PhishDestroy data: 728 flagged domains, 245 still alive, #3 worst registrar globally
PhishDestroy's analysis of 342 million domains across 104 registrars ranks UltaHost the #3 worst registrar in the world (risk score 68/100):
- ● 728 flagged phishing domains (up from 422)
- ● 433 formal abuse reports filed
- ● 245 domains still alive (33.7% alive rate)
- ● 58% of reported domains remain active after formal complaints
- ● 98.4% confirmed malicious by VirusTotal
Industry directories openly classify UltaHost as bulletproof hosting
Four independent classifications now name UltaHost as bulletproof hosting:
- ● Bolster AI — anti-phishing cybersecurity firm
- ● HostAdvice — “8 Best Bulletproof Hosting Providers” (calls UltaHost “the best”)
- ● WebsitePlanet — “7 Best DMCA-Ignored Hosting”
- ● OnlyLoudest — UltaHost ranked #2
These are third-party directory classifications, not regulatory findings. Their weight comes from UltaHost's own product line agreeing with them: the company sells “DMCA Ignored VPS” under that name.
ICANN records the breach as cured — 411 days after the notice
ICANN's compliance index records the breaches as cured on 23 March 2026 — 411 days after the 5 February 2025 notice, and three days after the fifth and final cure extension of 20 March 2026.
What “cured” means here is specific and limited: UltaHost satisfied ICANN on the contractual points in the notice — RDAP conformance, data escrow, and abuse-report handling records. It is a compliance finding about paperwork and process. It is not a finding that abuse on the platform stopped, and ICANN does not claim otherwise.
58 ads claimed 100% uptime, including during the June–July outage
Across the same 166-ad dataset, UltaHost ran three mutually inconsistent uptime figures at the same time. This does not require an external source to establish — the contradiction is internal to the company's own advertising.
- ● 58 ads claim “100% uptime” (17 active), running March 5 – August 3, 2026
- ● 36 ads claim 99.9% uptime (8 active), from April 10, 2026
- ● 3 ads claimed 99.99% in Sept–Oct 2025; ultahost.com still headlines a “99.99% Uptime Guarantee”
The 100%-uptime window fully contains the Istanbul storage-node degradation of June 22 – July 3, 2026 documented in Round 6, and it postdates the independent one-month test that recorded 43.78% uptime with 17 days down. No hosting provider can deliver 100% uptime, and UltaHost's own contractual figure is lower than what these ads assert.
The 4.9 rating claim runs in 101 paid Meta ads
Round 6 documented the gap between UltaHost's advertised 4.9 and its actual Trustpilot score. Round 7 establishes where that number is being distributed: Meta's public Ad Library holds 166 UltaHost ads archived between August 21, 2025 and August 3, 2026, of which 43 were still active when we pulled the dataset.
- ● 101 of 166 ads carry a 4.9/5 rating claim; 33 were active
- ● 41 ads render it as “Rated 4.9/5 by 1900+ Users”
- ● UltaHost's own homepage shows the figure on a badge/trustpilot.png image whose alt text reads “Rated 4.9 from over 1000 reviews”
- ● Its VPS page states “4.9 out of 5 based on 1,932 UltaHost Review”
- ● Trustpilot showed TrustScore 3.6, displayed as 3.5 stars, from 1,739 reviews on August 4, 2026
The ads ran on Facebook, Instagram, Messenger and Audience Network. 122 of the 166 carry European Union transparency data under the Digital Services Act, reaching 33 EU countries. We make no allegation about intent; we record that a 4.9 figure attributed to Trustpilot was placed in paid distribution while Trustpilot displayed 3.6.
UltaHost concedes in public: "waiting 24+ hours without a clear status isn't ok"
On a customer posted to r/Hosting under the title “Is Ultahost a scam?”, describing paying for a VPS in South Korea and not receiving a working server. The following day UltaHost's own account replied:
“Hey UltaHost here! Sorry you’re dealing with this. Packet loss on a fresh VPS is not normal and waiting 24+ hours without a clear status isn’t ok either.”
Answering customers in public is to the company's credit, and we say so. The reason it is recorded here is that it is a first-party admission: the provider itself characterising both the technical fault and the support delay as not acceptable, in a thread asking whether it is a scam.
PhishDestroy begins systematic flagging of UltaHost phishing domains
Independent anti-phishing organization PhishDestroy begins filing formal abuse reports on domains registered through UltaHost. By the end of February 2026, the count reaches 422 flagged phishing domains. The majority remain live after reports.
ICANN cure deadline passes — followed by five separate cure extensions
The 21-day cure period expires without demonstrated compliance. Rather than move to suspension or termination, ICANN grants a series of extensions. Its own compliance-notices index records five, each a separate dated entry:
- ● 7 March 2025
- ● 17 April 2025
- ● 29 April 2025
- ● 9 June 2025
- ● 20 March 2026
The breach was ultimately recorded as cured on 23 March 2026 — 411 days, or about 13.5 months, after the 5 February 2025 notice.
Read the extensions carefully: they are evidence about ICANN's enforcement posture as much as about UltaHost. Granting more time is within ICANN's discretion and is not itself misconduct by either party.
ICANN issues official Notice of Breach to UltaHost
ICANN's compliance division issues a formal Notice of Breach to UltaHost (IANA #4331) for violations of the Registrar Accreditation Agreement:
- ● RAA §3.18.2: failure to mitigate DNS abuse
- ● RAA §3.18.4: failure to provide abuse records
- ● RDAP non-compliance: no IPv6, conflicting version info
- ● Data escrow, contact info, and policy disclosure failures
UltaHost is given 21 days to cure the breach (deadline: 26 February 2025). This is one of only a very small number of such notices issued to any registrar in 2025.
UltaHost has ZERO .com domain registrations
DomainNameWire reports: “Ultahost signed its accreditation agreement in September and was assigned IANA#4331. As of the end of October, it had no .com registrations.” Their entire registrar business launched with zero legitimate .com customers — suggesting the registrar accreditation was sought to attract abuse-friendly business from the outset.
[SUPERSEDED — updated Aug 8, 2026] Accurate at the end of October 2024, and no longer the current position. ICANN's own monthly registrar transaction reports show IANA ID 4331 going from 0 .com domains under management (Oct 2024) to 25,179 (April 2026, the latest published month). The launched-with-no-customers observation stands as a fact about October 2024 — it is not a description of the registrar today.
RIPE NCC assigns Autonomous System AS214036 to UltaHost
UltaHost operates its own autonomous system, ULTAHOST-AS. Read directly from RIPE's registry and routing data:
- ● 86 announced prefixes
- ● 7 upstream carriers including Cogent (AS174), and zero downstream customers — a leaf network buying transit, not selling it
- ● No internet-exchange presence (PeeringDB: 0 IXs, 16 facilities)
- ● Registered abuse mailbox: u-abuse@ultahost.com
- ● Maintained under NETROUTING-MNT
For completeness, and against our own argument: AS214036 is not on the Spamhaus ASN-DROP list. We checked, and we report the negative.
UltaHost signs ICANN Registrar Accreditation Agreement
Assigned IANA registrar ID #4331. UltaHost is now contractually obligated to follow ICANN's Registrar Accreditation Agreement (RAA) including Sections 3.18.2 (mitigate DNS abuse) and 3.18.4 (provide abuse records).
ULTAHOST LTD UK incorporated as a £10,000 shell company
Companies House registration No. 14567126:
- ● Registered office: 71-75 Shelton Street, Covent Garden, London — mass-registration address used by thousands of shell companies
- ● Sole director AND sole secretary: Elin Doughous (Turkish nationality, recorded as resident in Turkey)
- ● Share capital: £10,000 (minimal)
- ● 75%+ ownership and voting rights held by single individual
UltaHost Inc. incorporates in Delaware, USA
Registered to 651 N Broad St Suite 206, Middletown, DE — a mass-corporate-services registered-agent address, not an operational office. UltaHost's own terms name the Delaware entity, and its BBB profile (file opened Jan 2, 2024) carries the same address.
What we could not check: Delaware's entity search is CAPTCHA-walled to automated retrieval, and Delaware does not publish officers or directors in any event. So the incorporation year is corroborated from secondary records rather than read off the state register, and there is no official officer list to compare against the UK filing.
Doughouz family founds operations in Istanbul, Turkey
Elin Doughouz and Deen Doughouz (later joined by Younes Doughouz) begin running tech ventures from Turkey under the Doughouz Group name, which is associated with ScriptSun, WoWonder, PlayTube, DeepSound, PixelPhoto and Wolvor Global (“Military technology providers”).
Why this is corroborated and not verified: no primary record of a 2018 founding exists in any register we can reach. The year rests on Crunchbase and on the subject's own interview in Disrupt Magazine — usable as a self-admission, not as independent confirmation. Other materials give “2018/2019”, so treat the year as approximate.
Have an incident to report?
If you experienced data loss, an unexplained suspension, an ignored abuse report, or a refund dispute with UltaHost, submit your story — anonymously if you prefer. Every verified report strengthens the public record. See also our methodology for how entries are verified before publication.