Round 9 — published

Round 9 Investigation: Registrar and Host

August 2026 — Round 8 showed scam sites running on UltaHost's own shared hosting. The obvious defence was available to them: a host cannot vet every customer. This round closes that defence on one specific domain, where UltaHost is simultaneously the company that sold the name, the company that serves the page, and the company whose published policy says sites like it are disabled immediately.

9.1 They Registered It, They Host It, and It Is Still Up

spx40k-fxempire.com is a cryptocurrency presale page. It is also a clone of an article from FX Empire, a real financial-media publisher: it carries the byline “By : FXEmpire”, a cloned author biography claiming “over 28 years of experience in the financial industry”, and FX Empire's own legal disclaimer copied word for word. The brand name appears more than 200 times on the page.

Three records, one company

RegistrarUltahost, Inc., IANA ID 4331— from Verisign's authoritative .com registry, not a reseller database
Host192.142.10.5, reverse DNS cp11.ams1.ultacp.com— UltaHost's own managed cPanel plane
TimelineRegistered ; still returning HTTP 200 with the same 184 KB page when re-checked on — day 17, registry status still active

UltaHost's abuse policy states that for “phishing attempts, malware distribution, financial scams, or child exploitation content… the domain will be immediately disabled without prior notice.” Sixteen days is not immediately.

The part that cuts in UltaHost's favour — and why it matters

Three sibling domains registered through UltaHost have been dealt with. gro24h-cointelegraph.com and gro24h-cryptoslate.com, both registered on 26 June, now carry the registry status client hold and no longer resolve. spxpresale-cryptoslate.comredirects to cPanel's “Account Suspended” page. So UltaHost can suspend a domain, and does.

That is what gives the remaining one its weight. The question is not whether they are capable of enforcement. It is why the newest domain in an obvious cluster — same naming pattern, same server, same scheme — was still serving a fortnight later.

Limits. We are reporting a registry record, a DNS record, and a page we retrieved and archived. We do not assert that anyone at UltaHost saw this domain or received a report about it. VirusTotal currently records two vendors marking it suspicious and none malicious — so the impersonation, which is plain on the face of the page, is the evidence here rather than any vendor score.

9.2 197 Flagged Domains on Four Servers

Round 8 counted 20 scam domains on the cPanel plane by filtering scans whose reverse DNS happened to be captured. Querying the four cPanel IP addresses directly returns an order of magnitude more.

536
distinct domains seen
197
flagged phishing / malware / fraud
118
on one server alone

These are not isolated registrations but recurring campaigns:

  • Hardware-wallet phishing — a Ledger firmware set including the typosquat leedger-firmware-update.com
  • A two-factor-authentication kitsecurebo-, onlinebo- and verifybo-2fauser.com
  • Government impersonation in three countriesirsgovtax.xyz (US tax), echallan-parivahan.com (India's traffic-fine portal) and dubaichamberpay.com
  • 35 domains tagged advance-fee fraud, 28 tagged cryptoscam, 91 serving an open directory

This is happening now, not historically

By month first seen: 11 in June, 118 in July, and 60 in the first twenty days of August. ICANN recorded UltaHost's registrar breach as cured on . Five months later the flagged-domain count on these servers is rising, not falling.

Limits.A urlscan tag is a scanner's classification, not a finding of fact, and part of any rise reflects more scanning rather than more abuse. The dates are when a domain was first scanned, which is a floor on when it existed, not a registration date.

9.3 African Addresses, Administered From a Gmail Account

We resolved all 86 prefixes UltaHost announces to whichever registry actually governs each one. Seventeen are not administered by RIPE at all — and thirteen of those belong to AFRINIC, the African internet registry, held by an entity recorded as “Ultahost RR” but registered to the Netherlands and Spain, beneath a block AFRINIC allocated to a South African company.

Two of those African blocks are the ones this investigation keeps arriving at: 192.142.10.0/24, the cPanel server in section 9.1, and 192.142.18.0/24, whose address carried Cobalt Strike and Brute Ratel C4 command-and-control in Round 8.

The registered administrative andtechnical contact for that address space, in AFRINIC's public database, is ultahost@gmail.com.

This site has documented since Round 2 that a person trying to report a fraudulent site hosted by UltaHost was turned away for using a Gmail address. The company that would not accept an abuse report from Gmail lists a Gmail address as its own contact of record for the address space the abuse runs on.

What this is not. Using address space registered in another region is legal and ordinary — an IPv4 transfer and lease market exists for exactly this, and one further UltaHost block is openly leased through the IPXO marketplace. Netrouting, LayerSwitch, firstcolo and Pentech appear in these records as upstream carriers and sponsoring registries, notas UltaHost entities, and nothing here suggests otherwise. The narrow finding is that the infrastructure carrying the abuse is held at one remove from the operating company, in another continent's registry, behind a free email account.

9.4 A Fourth Company, Found in a Registry

UltaHost's terms name four jurisdictions — Dubai, Istanbul, the UK and the USA. Round 8 examined the UK arm and found it had filed dormant accounts three years running. The Istanbul arm has now surfaced, with a legal name, in the address registry:

ULTAHOST HOSTING VE VERİ MERKEZİ LTD. ŞTİ.

RIPE organisation ORG-UHVV1-RIPE · Yakuplu Mah., Hürriyet Blv., Skyport Residence, Beylikdüzü, Istanbul · holds 5 announced prefixes

Ltd. Şti. is the Turkish limited-company form, making this a distinct legal entity from both UltaHost Inc (Delaware) and the dormant ULTAHOST LTD (UK). Alongside it, RIPE holds two separate organisation objects for the Delaware company at the same Middletown address, and a further eight prefixes registered to a holder recorded only as “Private Customer” at “Private Residence”.

Reading this fairly.Operating companies in several countries is normal for a hosting business, and duplicate registry objects are usually administrative untidiness rather than design. We could not confirm the Turkish company's officers in any free searchable register, and we are not claiming it is hidden — only that a fourth corporate identity exists, holds real infrastructure, and was discoverable from the address registry rather than from anything the company publishes about itself.

9.5 38% of Customer Sites Fail HTTPS

We sampled 32 sites sharing UltaHost's four managed cPanel servers and inspected the certificate each actually presents to a browser. Twelve fail:

FailureCountDetail
Expired certificate1007truckingcorp.com — expired 86 days ago
Self-signed certificate3all issued by globaloffshoremargin.com
Certificate for another domain6see below
Domain dead entirely2no DNS resolution

The wrong-certificate cases are the revealing ones. Three unrelated businesses — 01kexchange.com, ai-findsignals.com and odmastery.academy — are each served a certificate issued for cpcontacts.webadormyappiiclohelverydssxc.com. Two more are served one belonging to another customer, fasttransitlogistic.com. A sixth gets the server's own hostname, lax007.arandomserver.com.

This is a platform failure, not customer error. cPanel — the control panel UltaHost sells with these plans — includes AutoSSL, which issues and renews certificates automatically at no cost. Every visitor to these sites sees a full-page browser security warning instead of the site they asked for.

Method. 32 sites chosen by stepping evenly through the reverse-DNS list for each IP rather than taking the first alphabetically, with flagged, gambling and adult domains excluded. Every certificate was inspected directly and each classification re-confirmed independently with openssl. A 32-site sample supports the proportion loosely, not to the percentage point, and any one certificate may have been fixed since we looked.

9.6 What Customers Actually Say

Reddit is one of the few places left where hosting reviews are not affiliate-funded, and one poster went looking for exactly that: “Most of the reviews I’ve found online are clearly affiliate-driven or surface-level, which isn’t super helpful.” We collected the threads that mention UltaHost by name across r/webhosting, r/Hosting and r/selfhosted, and read the Trustpilot profile directly.

An outage, two subreddits, and silence

Two separate threads about the same incident, posted within about a fortnight of this report. One is titled “UltaHost Outage 8/6 to…”:

“Is anyone aware what’s going on with UltaHost? It’s day 2 of an outage with no new updates and now I can[’t] get into their Control Panel”

“These updates don’t need a lot of detail. I came to Reddit to see if anyone else had info. because I wasn’t getting any from Ultahost.”

A commenter in the parallel r/Hosting thread points at the specific machine — “Are you on their Frankfurt server (CP3)?”— and links UltaHost’s own status page. That page removes any need to take a stranger’s word for it:

“We are currently performing the final migration and performance maintenance on the shared hosting server CP3 (79.133.41.61)in Frankfurt… users may experience degraded performance or temporary service unavailability, including intermittent access to websites and the control panel. At this time, there is no confirmed ETA… We expect the maintenance to be [f]ully resolved within the next 24 hours.”

— ultahoststatus.com, incident “CP3 Shared Hosting Server – Final Migration & Performance Maintenance”. Marked Resolved roughly three days later, not twenty-four hours.

Note the address.UltaHost’s own status page identifies CP3 as 79.133.41.61. That is the same server that section 9.2 found carrying 118 flagged domains— more than the other three cPanel boxes combined. The customers sitting through this outage were sharing a machine with the largest concentration of flagged scam domains we found anywhere in UltaHost’s estate.

Trustpilot, read the same week

Trustpilot sits behind a web application firewall that refuses datacentre traffic, so this is a rendered capture of the ordinary public profile taken on . Its own published aggregate: TrustScore 3.5 from 1,750 reviews — down from 3.6 when we last read it on 4 August. The distribution stays bimodal: 64% five-star, 26% one-star, 10% in between.

The 17 reviews visible in that capture run to and split 9 negative to 8 positive — a far worse ratio than the lifetime 64% five-star, and the negatives cluster on exactly the week of the CP3 migration.

“currently my 2 websites are down (and have been for a 3 days) and they only thing they say is that they are sorry but they are doing upgrade at Frankfurt(???????) location. no warning, no notice before doing anything. avoid” — 2★, 8 Aug 2026

“Terrible service. They have a lot of downtime. They migrate server once every month so you have a downtime for days.” — 1★, 7 Aug 2026

That first review is a customer describing, from the outside, the same Frankfurt migration UltaHost documented on its own status page and two Reddit threads tracked independently. Three separate sources, one incident.

A customer says the DMCA-ignored product was not DMCA-ignored

“They said it’s dmca ignored before buying but after it turned out that it’s not!!! THEY SUSPEND YOU WEBSITE WITHOUT YOUR NOTICE!!! ABSOLUTE SCAAAM” — 1★, 15 Aug 2026

Round 8 documented UltaHost selling “Offshore DMCA Ignored VPS Hosting” as a named product. This is the other end of that transaction: someone who bought it and says the promise did not hold. We cannot verify their account — we have no access to their ticket history or to whatever was hosted — and it is possible the content breached a different term. It is published as a dated customer allegation that lines up precisely with a marketing claim we verified independently.

100% of negative reviews answered. The support ticket closed itself three times.

Trustpilot’s profile states that UltaHost “Replied to 100% of negative reviews”. That is the platform’s own counter, and it is a real credit. Set it beside a review posted on :

“I was locked out of my macOS VPS for two weeks due to an ‘infrastructure outage’. Their automated system closed my support ticket three separate times while I was still waiting for a fix. After eight days of downtime, I explicitly told support: ‘I don’t need any data on the VPS. Can you simply give me access to a new one that works?’ Instead of helping, they auto-closed the ticket again. Five days later, a rep finally responded to ask: ‘Please let us know whether you have any important data stored on your server.’ There was no follow-up during this time unless I initiated.”

This is the pattern Round 8 called responsive where it is scored, silent where it is not, now in one customer’s account: a public reply rate of 100% on the channel that publishes a number, and a support queue that closed the same person’s ticket three times. Trustpilot’s counter also now reads “typically replies within 2 weeks”; when this site last recorded it, it said one.

A VPS customer alleging compromise

A post titled “Stay Away from Ultahost”, cross-posted to r/Hosting and r/webhosting:

“My Ultahost VPS keep getting infiltrated, sketchy AF. I’m moving on and recommend staying away”

“I tried out ultahost for a Windows VPS and very quickly started experiencing tons of forced restarts of my server, and then 2-factor apps tabs/searches/extensions I did not search for being googled and added to my machine. There were also backdoor admin accounts that were added.”

“I came back, and THEY had disabled norton endpoint protection and there were 2 backdoor admin accounts re-added to the machine!”

Treat this as an allegation, because that is what it is.It is one customer’s account of their own server, unverifiable by us or by any other reader, and a compromised Windows VPS has many possible causes that have nothing to do with the provider. We include it because it is a specific, dated, first-hand report rather than a vague complaint — and we flag that the same poster notes they initially confused the company with the similarly-named Ultrahost.

The company answering in public

In a thread bluntly titled “Is Ultahost a scam?” (r/Hosting, posted ), a customer describes paying for a South Korean VPS and not getting a working one. UltaHost’s own account replied the next day:

“Hey UltaHost here! Sorry you’re dealing with this. Packet loss on a fresh VPS is not normal and waiting 24+ hours without a clear status isn’t ok either.”

That is the company conceding, in its own words, that both the fault and the support delay were unacceptable. A separate thread records a WordPress customer’s verdict — “Terrible experience with the Ultahost Business Hosting plan for a WordPress online store. Without contacting support, most of the advertised features don’t work” — under the title “I added Ultahost to the blacklist”.

And the customers who are happy

They exist, and leaving them out would make this section propaganda. A user who moved from Hostinger reported: “the switch made sense for me, mostly because of cheaper solution and more stability”. Others: “I’ve not experienced this with UltaHost. Ive been using them for months without issue” and “It is great with ultahost, I myself is using it for the last 1 year.”

The honest summary of Reddit is not “everyone hates them”. It is that the volume is low, the positive reports are ordinary and unremarkable, and the negative ones cluster around two specific things this report measured independently: outages on named servers, and support that goes quiet. One reply to the happy migration post is worth noting for its scepticism rather than its evidence: “just wait until you eventually migrate to an actual decent host in less than 18 months.”

Retrieval note. Reddit closed its logged-out interfaces during this investigation: old.reddit.comnow redirects every logged-out request to a login page, and the JSON endpoints refuse us outright. We also found that one automated tool reported success on a Reddit JSON URL while actually returning the site’s HTML shell — a false success we caught and discarded rather than published. These quotes come from rendering the ordinary public pages. Reddit search surfaces related posts in a sidebar, so a quote can appear on several thread pages; each one above is attributed to the thread it was actually posted in.

9.7 What We Tested and Did Not Find

Three checks in this round came back against us. They are here because a site that only publishes the findings that suit it is not worth reading.

UltaHost is not slow

Slowness is asserted about this company constantly, so we measured it: 296 samples across 37 hosts from three independent vantage points, reporting server processing time (the interval after the TLS handshake and before the first response byte, which excludes network distance). Median 12ms; 36 of 37hosts inside Google's “good” threshold of 800ms; nonein the “poor” band. Whatever is wrong here, raw server speed is not it.

Google is not blocking these domains

We checked all 64 domains from Round 8 and this round against Google Safe Browsing — the list Chrome and Firefox actually enforce. Zeroare flagged. We ran a positive control against Google's own test URLs first, so the zero is a real answer and not a broken query. Safe Browsing matches specific URLs rather than bare domains and its entries expire, which limits what a negative proves — but it is a negative, and it is ours to report.

AbuseIPDB scores are low

The eight IPs in this investigation carry AbuseIPDB confidence scores between 0% and 33%, with single-digit report counts on most. That is not the profile of an address range the internet has collectively condemned, and anyone citing this site should know it.

One further disclosure about our own method. The speed measurement initially produced a nonsense result: 106 of 296 samples returned HTTP 000and our aggregation counted that as a valid status, scoring eleven unreachable sites as “0ms, good”. They were not fast — they were not answering. Chasing that mistake is what produced section 9.5.

9.8 Verify It Yourself — And Our Method

Every figure above comes from a record you can open. The registrar claim in 9.1 is the one to check first, because it is the one that matters most and takes ten seconds.

SourceWhat we took from itWhere
Verisign RDAP (.com registry)Registrar of record, registration date, registry statusrdap.verisign.com — spx40k-fxempire.com
urlscan.ioEvery scan on the four cPanel IPs, with classification tagsurlscan.io — page.ip:79.133.41.61
VirusTotalPer-domain vendor detections and registrar metadatavirustotal.com — domain reports
AFRINIC RDAPWho holds the address space, and its contact of recordrdap.afrinic.net/rdap/ip/192.142.10.0
RIPE RESTOrganisation objects behind every announced prefixrest.db.ripe.net — ORG-UHVV1-RIPE
Google Safe Browsing v4Whether browsers block these domains (they do not)safebrowsing.googleapis.com
AbuseIPDBThird-party abuse reports against the IPsabuseipdb.com/check/159.100.6.5
Trustpilot profile (rendered capture)TrustScore, review count, distribution, reply-rate counter, recent reviewstrustpilot.com/review/ultahost.com
UltaHost's own status pageCP3 Frankfurt identified as 79.133.41.61; outage start and resolutionultahoststatus.com — CP3 incident
UltaHost's own abuse policyThe suspension promise this round measures them againstultahost.com/abuse-handling-policy

Method, including its limits

  • Retrieval. All of it read directly over HTTP on . No commercial scraping service was involved in any registry, certificate or scan finding. The scripts are in the site's repository and print the figures published here.
  • Sampling. The certificate study is 32 sites of several hundred on those servers. The VirusTotal pass covers 24 domains, limited by its four-requests-per-minute free tier. Neither is a census.
  • What we could not reach. urlscan's wildcard search needs an account we do not have, so we queried by IP instead. PageSpeed Insights was unavailable. The Turkish company could not be confirmed in a free searchable register.
  • No comparison group.We measured no other host's certificates, servers or address space. Nothing here says UltaHost is worse than its competitors on these measures — every finding is measured against UltaHost's own published policies.
  • Archiving. The live scam page in 9.1 was captured and stored, because it is the claim most likely to change after publication — and we would rather it did.

9.9 Editor's Conclusion

Every round until now could be met with the same answer: a large host cannot police every customer, and bad things land on cheap infrastructure everywhere. Section 9.1 is not answerable that way.

UltaHost sold the domain. UltaHost serves the page. The page impersonates a real financial publisher by name, byline and copied legal text, to promote a crypto presale. Their own policy promises that financial scams are disabled immediately and without notice. Three near-identical sibling domains were suspended — so the capacity and the willingness both exist. This one was registered on 4 August and was still returning a 184 KB page on 20 August.

Behind it sits the pattern the rest of this round documents: 197 flagged domains across four shared servers with the monthly count rising five months after ICANN closed its breach case; address space drawn from the African registry and administered through a free Gmail account by a company that refused an abuse report for coming from Gmail; a fourth corporate identity visible only in a routing database; and 38% of sampled paying customers served a browser security warning because nobody renewed a certificate that renews itself for free.

And the things we checked that did not hold. They are not slow — they are fast. Google does not block these domains. AbuseIPDB barely registers them. We went looking for those answers and we are printing the ones we got.

Round 8 concluded that UltaHost's stated policies and its actual infrastructure were two different things. Round 9 narrows that to a single domain where the company occupies every role at once — seller, host, and the party that promised to switch it off — and where, sixteen days on, it had not.