Round 10 Investigation: The Paper Trail
August 2026 — Round 9 proved that UltaHost was both the registrar and the host of one scam domain. This round follows that thread into the places where such things leave paper: a federal court docket, a registrar abuse index, the sanctions lists, and the full abuse record of every address block the company announces. One of the things it turned up is a mistake of our own.
10.1 A Federal Court Record, At Last
Round 8 searched the free court record and found nothing, and Round 9 retracted an older claim that UltaHost was “stonewalling actual lawsuits”. That search missed one case for an embarrassingly small reason: it queried "Ultahost, Inc" with the comma. Drop the comma and a federal docket appears.
TelevisaUnivision, Inc. and Televisa, S. de R.L. de C.V. v. Luis Fermín Gil Alphand, et al.
US District Court, Southern District of Florida · 1:26-cv-23911-KMW · filed · nature of suit 820 Copyright · cause 17 U.S.C. §504 · preliminary injunction entered
The injunction targets four pirate IPTV services — Roja Directa, Tarjeta Roja, PirloTV and XuperTV — and attaches a schedule of the intermediaries that serve them. Entry 81 reads:
“Ultahost, Inc. — Domain registrar (Roja Directa)”
And the operative clause reaches registrars directly: “at Plaintiffs' election, any domain name registrars or registries or others with access or control of said domain names are hereby ordered to delete, cancel, disable, and/or transfer to Plaintiffs any such domain names so that they may no longer be used for unlawful purposes.”
What this is not — and if you take one thing from this section, take this
- ● UltaHost is not a defendant. The defendants are named individuals and companies, plus John Does.
- ● Well over a hundred intermediaries are on the same schedule (entries 22 to 137), including GoDaddy, Akamai, Squarespace Domains, eNom, EuroDNS, Sav.com, LeaseWeb, Liquid Web, Newfold Digital, Vercel, Automattic, Canva and even the RIPE Network Coordination Centre. Nobody thinks Canva or a regional internet registry is running a piracy ring — appearing on this schedule is routine anti-piracy procedure and is not evidence of wrongdoing by anyone on it.
- ● The plaintiffs distinguished between the two kinds of intermediary, which is the useful detail. Four companies were originally named as defendants and then voluntarily dismissed — Enzu LLC, Dash Networks Inc., Digital Ocean LLC and HostGator LLC. UltaHost was never in that group: it appears only in the schedule of third parties.
- ● We cannot say whether UltaHost complied. The order operates only at the plaintiffs' election, and we do not know what was elected or when.
What is fairly reportable is the juxtaposition, and it is a sharp one. A company that sells “Offshore DMCA Ignored VPS Hosting” as a named product, promising buyers they can “avoid copyright issues”, now appears in a US federal copyright injunction as the registrar of record for one of the longest-running piracy brands on the internet. GoDaddy does not advertise DMCA-ignored hosting.
10.2 1,134 Domains Registered Through Them
Round 9 sampled 24 scam domains on UltaHost's own servers and found 9 registered through UltaHost too, and said the pattern probably ran wider. PhishDestroy indexes phishing by registrar of record, which answers exactly that question.
Coverage begins , so that is roughly thirteen months of registrations. 800 of the domains carry a VirusTotal score of 5 or more. The registrar sits at a risk score of 68/100, ranked third worst, against 33,427 domains under the registrar in total. PhishDestroy's own conclusion, in its own words: “62% of these reported domains remain active, suggesting inadequate enforcement of abuse policies.”
We checked their attribution rather than trusting it
“Registered through UltaHost” is a strong claim, so we took five domains off that list and looked each one up in Verisign's authoritative .com registry. All five come back Ultahost, Inc., IANA 4331:
- ● coinmarketcaa.com — a CoinMarketCap typosquat
- ● safeurl-leedger.com and ledger-bank.com — Ledger hardware wallets
- ● coinbasepromotionclaims.com — Coinbase
- ● ultrexcapitalfx.com — a generic investment lure
Then we ran the same query against coinbase.com itself, which correctly returns MarkMonitor. The check discriminates between registrars rather than agreeing with whatever we point it at — which is the only reason the five positives mean anything.
The caveat on the trend
This site previously published 871 flagged and 374 alive (42.9%) as of 19 July. So the flagged count is up 263 and the alive rate is up almost nineteen points in about a month. We are notcalling that “enforcement got worse”, because part of it is arithmetic: domains added recently have had less time to be taken down, which lifts the alive rate on its own. The claims we stand behind are the raw count, the 98.5% VirusTotal rate, and PhishDestroy's own characterisation.
10.3 A Correction We Owe You
Round 9 published a section called “What we tested and did not find”, and one of the three items was that AbuseIPDB barely registered this company — confidence scores of 0% to 33%, described as “not the profile of an address range the internet has collectively condemned”.
That was true of the eight addresses we checked. It was wrong as a statement about the network, and the reason is a basic one: those eight addresses had been chosen to answer a different question — they were the shared-hosting and gambling IPs from the co-tenancy work — and eight addresses picked for one purpose are not a sample of roughly 22,000 for another.
Checking all 85 announced /24 prefixes gives this:
| Address | Reports | Confidence | Prefix |
|---|---|---|---|
| 192.142.37.70 | 275 | 100% | 192.142.37.0/24 |
| 84.200.24.229 | 229 | 100% | 84.200.24.0/24 |
| 159.100.19.157 | 116 | 100% | 159.100.19.0/24 |
| 79.133.56.174 | 103 | 100% | 79.133.56.0/24 |
| 84.201.25.69 | 99 | 100% | 84.201.25.0/24 |
| 202.155.11.65 | 28 | 97% | 202.155.11.0/24 (IPXO-leased) |
- ● 68 of 85 prefixes contain at least one reported address
- ● 191 reported addresses inside a 30-day window
- ● 20 addresses at confidence 75% or above, of which 14 sit at 100%
Several of the worst sit in the ranges Round 9 traced elsewhere: 192.142.37.70 and 192.142.53.10 are inside the AFRINIC space administered from a Gmail address, and 202.155.11.65 is in the block leased through the IPXO marketplace.
Why this is a section and not a silent edit
The original figure was given prominence becauseit was inconvenient for this site. A correction that runs the other way has to be given the same prominence, or publishing the first one was decoration rather than method. The lesson is unglamorous and worth stating: a sample selected to answer one question is not a sample for a different question. And the caution still cuts both ways — AbuseIPDB scoring is conservative, so a low score on any single address is not exoneration any more than a high one is proof.
10.4 The Owners: Nothing Found, and How We Looked
This site has said in several places that no personal legal actions or criminal allegations have been found against the founders individually. That was an assertion resting on our not having looked anywhere in particular. Here is the same statement with a method and a date attached.
| Source | Reached? | Result |
|---|---|---|
| OFAC SDN list (US Treasury) | Yes — 19,250 rows | No match |
| OFAC consolidated list | Yes | No match |
| UK OFSI consolidated list | Yes — 19,763 rows | No match |
| SEC EDGAR full-text search | Yes — one query of 15 returned a server error | No match on the 14 that answered |
| CourtListener, widened name shapes | Yes — one query of 24 was rate-limited | No match on any individual |
Terms screened: Doughouz, Doughous, Elin Doughouz, Elin Doughous, Elin Ander Doughouz, Deen Doughouz, Younes Doughouz, plus Ultahost, ScriptSun, WoWonder, Wolvor, Doughouz Group, PixelPhoto and DeepSound. Both surname spellings matter: ICANN addressed its breach notice to “Doughous” while Companies House and Crunchbase say “Doughouz”, and screening one spelling only is how this kind of exercise produces a false clean.
Two things the wider court sweep did surface
A full-text docket search on the surname returns five results, and we attribute none of them to anyone here. Three are US bankruptcy filings bearing the surname: two were filed in 1996 and 2002, when a person born in January 1992 was four and ten years old, and the third (2025) shares a surname and nothing else we can establish. The remaining two are not cases about anyone of that name at all — a criminal prosecution and the Tribune Media bankruptcy, where the string simply appears somewhere in the filing. They are listed here only because they are the first thing a careless search returns.
The entity sweep is what found the copyright injunction in 10.1 — which names the company as a third-party registrar, and no individual at all.
What a negative here does and does not mean
Sanctions lists name sanctioned persons. EDGAR covers US securities filings. A privately held hosting business and its owners would not normally appear in either, so finding nothing is the expected result rather than a clean bill of health. It rules out one specific category of allegation and nothing wider. Where a source could not be retrieved we record it as not checked— never as clean. Two individual queries did error out and are marked above: one SEC EDGAR term returned a server error and one CourtListener query was rate-limited. Neither is counted as a clean result.
In the same pass we removed two weak sources this site had been leaning on for personal claims: a commercial data broker and an open user-editable wiki. Neither belongs in a citation for a fact about a named individual. The claims that survived are the ones the UK statutory register supports, and where something rests on Crunchbase alone the page now says so.
10.5 What We Re-Checked
A watchdog site that only ever adds findings and never re-tests them becomes an archive. These are the previous rounds' claims, re-run on .
The Round 9 scam domain is still serving — day 20
spx40k-fxempire.com, registered through UltaHost on 4 August and hosted on its own cPanel server, still returns HTTP 200 with the same 184 KB FX Empire clone, and the registry still lists it as active — twenty days after it was registered. Its three sibling domains remain suspended.
ICANN has taken no further action
The compliance index still carries exactly one Ultahost row, ending with “Breaches Cured 23 March 2026”. No new notice, no reopened matter. A clean negative, and we report it as one.
Broken HTTPS moved the wrong way: 44% of sampled sites
Re-testing the same 32 customer sites, 14 now fail HTTPS in a browser rather than 12. The certificate faults are unchanged — one expired, three self-signed, six serving another tenant's certificate — and two more domains have gone dead entirely. Nothing was fixed in the intervening day.
10.6 Verify It Yourself — And Our Method
| Source | What we took from it | Where |
|---|---|---|
| CourtListener / RECAP | The copyright injunction and its schedule of intermediaries | courtlistener.com — 1:26-cv-23911 |
| PhishDestroy registrar report | 1,134 domains registered through Ultahost, Inc.; alive/taken-down split | phishdestroy.io — registrar report |
| Verisign RDAP | Independent registrar-of-record spot-verification, plus a control | rdap.verisign.com — coinmarketcaa.com |
| AbuseIPDB check-block | All 85 announced /24 prefixes | abuseipdb.com/check/192.142.37.70 |
| US Treasury OFAC | SDN and consolidated sanctions lists (19,250 rows) | sanctionslist.ofac.treas.gov |
| UK OFSI | Consolidated list of financial sanctions targets (19,763 rows) | gov.uk — OFSI consolidated list |
| ICANN compliance notices | Whether any new action followed the March cure (none) | icann.org/compliance/notices |
Method, including its limits
- ● The court documentsare the actual PDFs from the docket — a 37-page order and the 40-page report it adopts — retrieved and stored, not summarised from a news article.
- ● The registrar count is PhishDestroy's, not ours. We verified the attribution on a sample of five plus a control; we did not recount 1,134 domains, and a five-domain sample supports the attribution rather than proving every entry.
- ● Retrieval variance is real.A second urlscan pull the next day returned 1,193 scans where the first returned 1,400, because the anonymous search serves a shifting recent window. We are keeping the larger pull's figures and flagging this so nobody reads the smaller number as an improvement.
- ● What we could not reach. Sitejabber blocked every tier we tried, including paid residential, so it is recorded as not checked. Delaware's register remains CAPTCHA-walled, and neither Turkey nor the UAE publishes a free searchable judgment database.
- ● No comparison group.We did not screen any other host's owners or count any other registrar's phishing domains. PhishDestroy's own ranking is the only comparative figure here, and it is theirs.
10.7 Editor's Conclusion
Round 9 showed one domain where UltaHost was both the seller of the name and the server of the page. Round 10 is that finding with the paperwork attached.
A US federal court, granting a copyright injunction over four piracy services, lists Ultahost, Inc. as the registrar of record for Roja Directa. A registrar abuse index counts 1,134 phishing domains registered through the company across thirteen months, 698 of them still live, 98.5% of them flagged by VirusTotal — and five out of five, checked against the registry ourselves, really are registered there. Across the network, 68 of 85 address blocks carry abuse reports, with fourteen addresses sitting at 100% confidence and the worst carrying 275 reports. And the domain we wrote about yesterday is still serving today.
Now the other side of the ledger, because it is the reason the first paragraph is worth reading. UltaHost is not a defendantin that case, and GoDaddy and Akamai are on the same schedule — being listed is procedure, not proof. The rise in the alive rate is partly arithmetic, not necessarily worsening enforcement. The owners return nothingacross two governments' sanctions lists, US securities filings and a widened court sweep. ICANN has taken no further action. And this round exists partly to correct our own error: Round 9 told you AbuseIPDB barely registered this company, and that was wrong because we checked eight addresses instead of eighty-five.
Eight rounds asked whether UltaHost is a bad host. Two have now asked what it actually sells. The answer that keeps surviving contact with primary records is that it sells domains and hosting to people who need a registrar that will not look too hard — and that when someone finally does look, the paperwork is where you find it.