UltaHost Stats Dashboard
Every headline number on this site, with the direct link to verify the current value yourself. Click any source URL to confirm the data hasn't changed since we re-checked.
Last verified: We re-verify monthly. If a number here is stale, email contact@ultahostabuse.com and we'll update within 24 hours.
How fresh is this?
Most of these numbers come from sources that update in real time (PhishDestroy, AbuseIPDB, VirusTotal) or update daily (Spamhaus, BGP.HE.net, ICANN compliance reports). When you click through to the source, you're seeing today's value, not our snapshot.
Some numbers are from one-off reports (WebsitePlanet's 2026 uptime test, the ICANN breach PDF, UK Companies House filings). These are timestamped and don't change unless the filings are amended.
We re-check the whole dashboard monthly and update the “Last verified” date. If you find a number that's drifted, email contact@ultahostabuse.com.
How the numbers have evolved
- Feb 2026PhishDestroy domain count rises from baseline to 422
- Mar 2026ICANN breach 'cure' finally completed — 13 months past deadline
- Apr 18, 2026PhishDestroy count: 728 domains, 245 still live (33.7%)
- Apr 2026PhishDestroy registrar-stats ranking: UltaHost #3 globally (68/100)
- Apr 2026Four industry directories (HostAdvice, Bolster AI, WebsitePlanet, OnlyLoudest) classify UltaHost as bulletproof hosting
- May 17, 2026All site stats re-verified against live sources
- May 23, 2026Trustpilot ultahost.io profile review base grew to 833 reviews; bimodal pattern persists (57% five-star + 29% one-star, gap in the middle). PhishDestroy active-after-report tick-up to 58%. Fresh dated victim quotes May 11, May 12, April 11, March, January.
- May 24, 2026Headline Trustpilot rating on ultahost.com drops to 3.4/5 'Average' (was Excellent tier). 1,737 reviews on ultahost.com (2,570 combined across both profiles). Cybernews mainstream press now cites the April 11 forced-reboot case. Cloudflare community thread independently confirms abuse-ignore pattern on a Ledger phishing site. 3% Stripe gateway charge documented. Wikipedia article identified as reputation-laundering vehicle. January 2025 $2.4M infrastructure-investment claim flagged as unanswered funding question.
- Jun 9, 2026Named-campaign attribution: ~50 Ultahost-registered domains used in a coordinated Meta/WhatsApp/Instagram fake-job phishing operation with WebSocket-based 2FA/OTP interception (huskyscripts.blog IOCs; primary IP 160.30.169.150 on AS152983; C&C spyder1279.blog). WebsitePlanet 2026 review ranks UltaHost #3752 of 3,860 hosts (bottom 3%) with 43.78% measured uptime and 17 consecutive days down. Web Hosting Talk Dec 2024 thread documents UltaHost sending legal threats to a customer who won a credit-card chargeback. Counterfeit-currency hosting reported Dec 2025; abuse report rejected because the reporter used a Gmail address (procedural-pretext denial). AS214036 footprint snapshot: 49,239 domains on 5,553 IPs (~8.9 domains/IP, young ASN, high-churn pattern).
- Jun 16, 2026Quantified third-party fraud signal: Scamalytics rates UltaHost a 37/100 medium fraud-risk ISP — approximately 37% of observed UltaHost traffic flagged as potentially fraudulent across 24,512 tracked IP addresses. Casino-hosting own-contradiction surfaced: HostAdvice's June 2026 'Best Online Casino Hosting Providers' list features UltaHost while UltaHost's own ToS prohibits 'promoting gambling, casinos, gaming, sports betting' regardless of jurisdictional legality. Asymmetric enforcement pattern documented: multiple Trustpilot complaints describe paying customers' servers being suspended without notice or evidence on unsubstantiated phishing allegations — the same company that demands a trademark certificate or court order before investigating abuse reports against actual bad-actor customers. Second forced outage of April 2026 (April 26) added to the April 11 quant-trading-reboot incident already on record.
- Jul 1, 2026New multi-day outage cluster: third-party status trackers (StatusGator, EntireWeb, SaaSHub) recorded repeated 'Istanbul Storage Node Degradation' incidents across June 22–29, 2026 — UltaHost attributed the extended downtime to failed disks on a storage node and a slow data-rebuild/synchronisation, with concurrent warnings on Amsterdam and Toronto. A fresh, independently-monitored data point on top of the April 11 and April 26 forced-outage incidents already on record, against UltaHost's marketed '99.9% uptime guarantee' and the 43.78% uptime measured by WebsitePlanet. BBB letter grade ticked from D to D+ (still not accredited; 6 complaints, failure to respond to ≥1 — unchanged). PhishDestroy registrar rank (#3, 68/100) and 58% active-after-report rate re-verified unchanged.
- Jul 3, 2026Istanbul storage outage still unresolved: the 'Istanbul Storage Node Degradation' incident first logged June 22 has continued through July 2–3, making it an 11+ day storage failure rather than the June 22–29 window first recorded. StatusGator currently flags UltaHost's Amsterdam and Istanbul nodes as Down and Toronto as degraded — an active, multi-node major outage as of this update, corroborated by EntireWeb/SaaSHub (failed disks, recovery 'taking longer than anticipated'). Reframes the outage as ongoing against the marketed '99.9% uptime guarantee' and the 43.78% uptime measured by WebsitePlanet.
- Jul 19, 2026PhishDestroy totals re-verified against the registrar profile: 871 phishing domains now flagged through Ultahost, Inc. (up from 728 in April), 374 still alive (42.9%, up from 245/33.7%), 511 formal abuse reports filed since Jan 2, 2026 (previously 433). Registrar rank re-verified unchanged (#3 worst, 68/100). HostAdvice's casino-hosting guide re-verified — UltaHost still listed (#6) against its own ToS gambling ban. Phishing-tracker sample re-checked domain-by-domain: 19 of the 41 tracked domains previously marked LIVE now return NXDOMAIN and are re-marked offline; the aggregate still-alive count nonetheless GREW by 129 domains — takedowns are not keeping pace with new registrations.
- Aug 4, 2026Round 7 — first measurement of UltaHost's paid advertising. Meta's Ad Library holds 166 UltaHost ads (Aug 21, 2025 – Aug 3, 2026; 43 still active) across Facebook, Instagram, Messenger and Audience Network, 122 carrying EU Digital Services Act transparency data across 33 countries. 101 of the 166 advertise a 4.9/5 rating (41 as 'Rated 4.9/5 by 1900+ Users') while Trustpilot's measured TrustScore for ultahost.com is 3.6 from 1,739 reviews — up from 3.4 in May. Three simultaneous and mutually inconsistent uptime claims found: 100% in 58 ads (running Mar 5 – Aug 3, 2026, a window that fully contains the documented June 22 – July 3 Istanbul storage outage), 99.9% in 36 ads, and 99.99% on ultahost.com. Review-arrival analysis explains the reputation gap: of the 200 most recent Trustpilot reviews, company-invited reviews (135) are 70% 4–5★ while organic walk-ins (58) are 93% 1–2★, with only 8 reviews at exactly 3★ and 69% of reviewers having written just one lifetime review. No fabricated review text found — one duplicated body across 200 reviews. New two-source-verified case: a macOS server billed immediately and delivered unusable with refund refused, reported independently on Facebook (May 10) and Trustpilot (Jul 17). On whether UltaHost buys Facebook ad comments, no position is taken: all 166 ads are dark posts whose comment threads are visible only to the people served the ad, so the question cannot be verified or ruled out by any third party. Separately, the page's own 150 public posts carry 37 comments from 16 accounts with zero duplicate text across accounts and more complaints than praise — a description of the page timeline, not of the advertising. The previously tracked ultahost.io Trustpilot profile did not resolve on Aug 4 — one retrieval redirected to .com, another returned nothing; the combined 2,570-review figure is withdrawn pending manual verification.
- Aug 5, 2026Correction to Round 7 §7.5. As first published, that section said the purchased-Facebook-comment allegation had been 'tested and not supported' and that the page's engagement was 'low organic engagement, not manufactured engagement'. That overstated what had actually been measured. The 37 comments examined were on UltaHost's page TIMELINE; the advertising is a separate surface, and Round 7's own finding was that all 166 ads are dark posts whose comment threads no outside party can retrieve. A measurement of the timeline is not evidence about the ads. §7.5 and the editor's conclusion have been rewritten to state the limit rather than imply a clean result: the question is closed to third-party verification, this site takes no position on it, and the absence of access must not be read as an absence of wrongdoing. No measured figure changed — only the claims drawn from them.
- Aug 8, 2026Self-audit and corrections pass, published before the Round 8 report because a report about unsupported claims cannot rest on unsupported claims of its own. RETRACTED: the homepage assertion that UltaHost was 'stonewalling actual lawsuits filed against the company' — no citation existed anywhere on the site for it, and a keyless search of CourtListener/RECAP across opinions, dockets and document text returns zero results for Ultahost, Ultahost Inc., ScriptSun and WoWonder, as does the UK Find Case Law archive. The sourced claim that survives is narrower: a customer who won a card chargeback was told to expect legal action (WebHostingTalk, Dec 2024). CORRECTED: 'the HostScore lawsuit reviewer' to 'the HostScore reviewer' — that reviewer is nowhere a litigant. WITHDRAWN AS ENTITIES: 'ScriptSun Ltd' and 'Doughouz Group Ltd', including inside the site's JSON-LD structured data. A Companies House search returns zero UK companies named ScriptSun, WoWonder, Wolvor or Doughouz; only ULTAHOST LTD (14567126) exists on the UK register. ScriptSun and Doughouz Group are now described as brands attributed to Crunchbase, not as registered companies. SUPERSEDED: the 'zero .com registrations' finding, true at the end of October 2024, now carries ICANN's own monthly registrar transaction reports showing IANA ID 4331 at 25,179 .com domains as of April 2026. QUALIFIED: the '100% Trustpilot reply rate' is now stated as what it actually was — every one of the 200 reviews in our sample carried a reply, from a sample that reaches back only to Jan 23, 2026, and is not a lifetime rate. DOWNGRADED from verified to corroborated: the 2018 Istanbul founding (no primary record exists; the year rests on Crunchbase and the subject's own interview) and the 2021 Delaware incorporation (Delaware's register is CAPTCHA-walled and publishes no officers, so the year is corroborated from the BBB profile and UltaHost's own terms). RETRO-SOURCED: the ICANN accreditation now cites IANA's assignment list directly, and AS214036 has been rewritten from RIPE's own registry and routing data — 86 announced prefixes, 7 upstreams including Cogent (AS174), zero downstream customers, no internet-exchange presence, abuse mailbox u-abuse@ultahost.com, maintainer NETROUTING-MNT — replacing a figure that rested on bgpview.io, which is now NXDOMAIN and whose stat is frozen and labelled as such. The ICANN breach chain is now stated exactly: notice 5 Feb 2025, five separate cure extensions (7 Mar 2025, 17 Apr 2025, 29 Apr 2025, 9 Jun 2025, 20 Mar 2026), breaches cured 23 Mar 2026 — 411 days. AS214036 is NOT on the Spamhaus ASN-DROP list; we checked and we publish the negative. CLEARED: prose the Aug 5 correction missed — the homepage no longer characterises the two-Trustpilot-profile arrangement as deliberate manipulation, the withdrawn 2,570 combined review total is gone from the homepage and marked superseded on the May 2026 incident, the methodology page no longer instructs readers to compare a profile that did not resolve on Aug 4, and the Round 7 'did not hold' wording is now 'cannot be settled either way from outside the company'. Four statistics that cited bare domains now cite the actual records. PhishDestroy's active-after-report figure is no longer presented as a measure of registrar responsiveness, which PhishDestroy itself does not claim it is. Also fixed the research pipeline: the quote-picker required no mention of the subject, so a datacentre fire at an unrelated company and praise for a competitor had been surfacing as UltaHost findings.
- Aug 8, 2026Round 8 — 'The Business Model', the first round built almost entirely from primary records rather than customer reports. THE SPINE: two pages live on ultahost.com on the same day — a product page selling 'Offshore DMCA Ignored VPS Hosting' to 'avoid copyright issues', and an abuse policy claiming UltaHost 'strictly adheres to Section 3.18 of the Registrar Accreditation Agreement' and that domains involved in phishing, malware or financial scams are 'immediately disabled without prior notice'. INFRASTRUCTURE: abuse.ch URLhaus records 998 malware URLs on AS214036 (Feb 2022 - Aug 2026; volume PEAKED in 2025 at 528 and is LOWER in 2026 at 79, and only 54 are Windows crimeware rather than IoT-botnet noise); ThreatFox holds 9 command-and-control servers at 100% confidence, five of them red-team frameworks used by ransomware operators (Cobalt Strike, Sliver x2, Brute Ratel C4, Havoc), with 192.142.18.214 carrying two different frameworks ten months apart; urlscan shows 2,110 phishing scans inside the ASN (the unfiltered total is reported as at least 10,000 because that is urlscan's anonymous result cap, not a count). THE STRONGER SIGNAL IS THE PTR, NOT THE ASN: 20 distinct scam domains resolve to UltaHost's own managed cPanel control plane (*.ultacp.com), including a crypto-presale cluster impersonating FX Empire, CryptoSlate and Cointelegraph, two fake banks, and three Adobe lookalikes plus aliexpressboost.com — the trademark complaints UltaHost's own LinkedIn reply said it requires before investigating. GAMBLING vs THEIR OWN TERMS: all 120 distinct domains on 84.200.154.40 carry Indonesian gambling markers (28 explicit slot/bet/4D-togel, 92 matching the slot-brand naming convention, residual zero), against terms that prohibit promoting gambling 'regardless of the legality of such activities within your country'; the same IP served AgentTesla from a compromised WordPress install on one of those gambling sites. Our first classifier pass UNDERCOUNTED and was corrected — the method and its residual are published so the figure can be checked. ICANN'S OWN FILES: 19 months of monthly registrar transaction reports show IANA ID 4331 going from 0 to 25,179 .com domains, with no-grace deletions (registrar-initiated removals, not expiries) never exceeding 236 in any of the first 15 reported months and then running 332 / 1,399 / 1,283 / 1,032 in the four months to April 2026 — dated series placed side by side with the cure chain, with NO causation asserted. THE UK ENTITY IS DORMANT: ULTAHOST LTD (14567126) has filed dormant accounts for three consecutive financial years while UltaHost's own terms name 'UltaHost Ltd UK' as one of four operating jurisdictions; sole director AND secretary as two officer records for one person, 75-100% of shares/votes/appointment rights, ECCTA identity verification 21 Nov 2025, and ZERO other UK appointments. We explicitly REFUSE the same-address inference — 71-75 Shelton Street is a mass mail-forwarding address and 'N companies at this address' is worthless; officer-sharing is the only valid test and it returns nothing. LITIGATION: nothing in the free record — 16 CourtListener/RECAP queries and UK Find Case Law all return zero — reported as an absence of findings, not proof of no litigation, because RECAP holds only purchased dockets, BAILII was not checked, and neither Turkey nor the UAE publishes a free searchable judgment database. Five same-surname US bankruptcies are attributed to NOBODY: two were filed in 1996 and 2002, when a person born January 1992 was four and ten. PRIVACY: the director's full residential street address, previously published on this site in English and Turkish and in llms-full.txt down to the building and flat number, has been REMOVED. It appears in a pre-ECCTA statutory filing, but publishing a private individual's home address is a different act from reporting their directorship, and it supported no claim we make - 'Companies House records the director as Turkish and resident in Turkey' carries the operational-base point on its own. References to the home city have been reduced to country of residence throughout, and the address strings are now in the publish gate's blocklist so they cannot silently return.
- Aug 20, 2026Round 9 — 'Registrar and Host'. THE CENTRAL FINDING: spx40k-fxempire.com is a crypto-presale page that clones an FX Empire article — carrying the byline 'By : FXEmpire', a cloned author biography and FX Empire's legal disclaimer verbatim, with the brand name appearing over 200 times. Verisign's authoritative .com registry names Ultahost, Inc. (IANA 4331) as its REGISTRAR OF RECORD; it resolves to 192.142.10.5, whose reverse DNS is cp11.ams1.ultacp.com — UltaHost's own managed cPanel plane. Registered 4 Aug 2026, still returning HTTP 200 with a 184 KB page on 20 Aug. UltaHost is therefore both the seller of the name and the server of the page, against its own policy promising financial scams are 'immediately disabled without prior notice'. IN FAIRNESS, AND IT MATTERS: three sibling domains registered through UltaHost HAVE been dealt with — gro24h-cointelegraph.com and gro24h-cryptoslate.com carry registry status 'client hold' and no longer resolve, and spxpresale-cryptoslate.com redirects to cPanel's Account Suspended page. The capacity to suspend exists; the newest domain in the cluster was simply still up. SCALE: a full urlscan pull of four cPanel IPs returns 536 distinct domains of which 197 carry a phishing/malware/scam/fraud tag (118 on one box), with 11 first seen in June, 118 in July and 60 in the first 20 days of August — five months after ICANN recorded the breach cured. Campaigns rather than one-offs: a Ledger firmware phishing set incl. the typosquat leedger-firmware-update.com, a three-domain 2FA kit, and government impersonation in three countries (irsgovtax.xyz, echallan-parivahan.com for India's traffic-fine portal, dubaichamberpay.com). VirusTotal flags 17 of 24 domains checked, naming BitDefender, ESET, Kaspersky and Fortinet. ADDRESS SPACE: 13 of the 86 announced prefixes are AFRINIC (African registry) space held by 'Ultahost RR' but registered to NL/ES beneath a South African allocation — including the cPanel range hosting the scam cluster and the range that carried Cobalt Strike C2 — and the AFRINIC administrative and technical contact for it is ultahost@gmail.com, a free webmail account, from a company that refused an abuse report because the reporter used Gmail. One further block is leased through the IPXO marketplace. A FOURTH COMPANY: RIPE records ULTAHOST HOSTING VE VERI MERKEZI LTD. STI., an Istanbul-registered limited company holding 5 prefixes, alongside TWO separate organisation objects for the Delaware entity and 8 prefixes registered to a 'Private Customer' at a 'Private Residence'. SERVICE QUALITY: 12 of 32 sampled customer sites (38%) fail HTTPS in a browser — one certificate expired 86 days ago, three are self-signed by globaloffshoremargin.com, and six are served ANOTHER TENANT'S certificate (three unrelated businesses all present cpcontacts.webadormyappiiclohelverydssxc.com) — despite cPanel including free automatic SSL. CUSTOMERS: Reddit threads record a multi-day outage on CP3 Frankfurt (cp3.fra1.ultacp.com, one of the four servers measured here) with 'day 2 of an outage and no new updates', a WordPress customer titling their post 'I added Ultahost to the blacklist', and UltaHost's own account conceding in a thread titled 'Is Ultahost a scam?' that 'waiting 24+ hours without a clear status isn't ok'. Positive reports are included too. THREE FINDINGS AGAINST US, published as prominently as the rest: (1) we measured whether UltaHost is SLOW across 296 samples from three vantage points and it is NOT — median server response 12ms, 36 of 37 hosts inside Google's 'good' threshold, none 'poor'; (2) Google Safe Browsing flags ZERO of 64 domains, verified with a positive control against Google's own test URLs so the zero is real; (3) AbuseIPDB confidence scores on the eight IPs run 0-33%. Also disclosed: our first latency aggregation counted HTTP 000 (connection failure) as a valid status and scored eleven unreachable sites as '0ms, good' — chasing that error is what produced the certificate findings.
- Aug 21, 2026Trustpilot read directly for the first time in this investigation. The profile is behind AWS WAF - datacentre IPs 403, and both FlareSolverr tiers correctly DETECTED the challenge rather than returning it as a false success - so this is a rendered capture from a residential browser tier, verified as a genuine profile page by a STRUCTURAL test (does it carry the aggregateRating object and review bodies) rather than by substring, because Trustpilot ships an aws-waf token on its ordinary pages too and a substring test gives a false FAILURE. UPDATED FIGURES from Trustpilot's own published aggregate: TrustScore 3.6 -> 3.5, review count 1,739 -> 1,750. ⚠ A first parse reported 585 reviews - the profile page prints several FILTERED counts (585, 632, 25) beside the real one and a loose regex grabbed the wrong one; publishing it would have implied a thousand reviews had been deleted. The parser now reads the JSON-LD aggregate only. Distribution stays bimodal: 64% five-star, 26% one-star, 10% in between. THREE-SOURCE CORROBORATION of the early-August Frankfurt outage: UltaHost's own status page (CP3 = 79.133.41.61, 'no confirmed ETA', 24 hours promised and about three days taken), two Reddit threads, and a Trustpilot 2-star review reading 'my 2 websites are down (and have been for a 3 days) ... they are doing upgrade at Frankfurt (???????) location. no warning, no notice'. 79.133.41.61 is the server this investigation found carrying 118 flagged domains. NEW: a 1-star review dated 15 Aug states 'They said it's dmca ignored before buying but after it turned out that it's not!!! THEY SUSPEND YOU WEBSITE WITHOUT YOUR NOTICE!!!' - the customer-side counterpart to the DMCA-ignored product page Round 8 documented, published as an unverifiable but dated allegation. NEW: Trustpilot's own counter credits UltaHost with 'Replied to 100% of negative reviews', which SOURCES the 100% figure this site had previously qualified as sample-only - set against a 1-star review of 18 Aug describing two weeks locked out of a macOS VPS with the support ticket 'closed ... three separate times' automatically. The same counter now says 'typically replies within 2 weeks' where it previously said one. Of the 17 reviews in the capture (22 Jul - 18 Aug), 9 are 1-2 star against 8 at 4-5 star, and the negatives cluster on the migration week. ALSO FIXED: Round 7's key-facts box interpolated the LIVE TrustScore into a page reporting a 4 Aug measurement, so every future Trustpilot movement would silently rewrite a dated finding; those figures are now pinned to their measurement date. Re-verified spx40k-fxempire.com on 21 Aug: still HTTP 200, same 184 KB page, registry status still active - day 17. Its three siblings remain suspended.
- Aug 24, 2026Round 10 - 'The Paper Trail'. FIRST FEDERAL COURT RECORD: TelevisaUnivision, Inc. v. Gil Alphand (S.D. Fla., 1:26-cv-23911, nature of suit 820 Copyright, 17 USC 504). The preliminary injunction entered 24 Jul 2026 lists at entry 81 'Ultahost, Inc. - Domain registrar (Roja Directa)' and orders that at the plaintiffs' election any registrar with control of the infringing domains delete, cancel, disable or transfer them. Round 8 missed this case because it queried 'Ultahost, Inc' WITH the comma; without it the docket appears. ⚠⚠ESSENTIAL CONTEXT PUBLISHED WITH IT: UltaHost is NOT a defendant, well over a hundred intermediaries are on the same schedule (entries 22-137) including GoDaddy, Akamai, Squarespace Domains, eNom, EuroDNS, Sav.com, LeaseWeb, Newfold Digital, Vercel, Automattic, Canva and the RIPE Network Coordination Centre, appearing there is routine anti-piracy procedure and not evidence of wrongdoing. ⚠A FIRST DRAFT OF THIS ENTRY LISTED HOSTGATOR AS ONE OF THOSE NEUTRAL CO-LISTED INTERMEDIARIES, WHICH WAS WRONG: HostGator LLC was one of FOUR companies originally named as DEFENDANTS and later voluntarily dismissed (with Enzu LLC, Dash Networks Inc. and Digital Ocean LLC). An adversarial check caught it before publication. UltaHost was never in that group, and we CANNOT say whether UltaHost complied because the order acts only at the plaintiffs' election. REGISTRAR AT SCALE: PhishDestroy counts 1,134 phishing domains registered THROUGH Ultahost, Inc. (coverage from 23 Jul 2025), 698 still alive, 436 taken down, 98.5% VirusTotal-flagged, 800 at VT score >=5, registrar risk 68/100 ranked 3rd worst against 33,427 domains total; their own words: '62% of these reported domains remain active, suggesting inadequate enforcement of abuse policies'. We spot-verified the attribution 5 of 5 against Verisign RDAP (coinmarketcaa.com, safeurl-leedger.com, ledger-bank.com, coinbasepromotionclaims.com, ultrexcapitalfx.com all = Ultahost, Inc. IANA 4331) WITH A NEGATIVE CONTROL (coinbase.com correctly returns MarkMonitor). Site figures updated 871->1,134 and 374->698; ⚠the alive-rate rise 42.9%->61.6% is NOT published as 'enforcement got worse' because part of it is a cohort effect - recent additions have had less time to be taken down. ⚠⚠CORRECTION TO OUR OWN ROUND 9: that round published 'AbuseIPDB scores are low (0-33%)' as a finding AGAINST this site. That was true of the 8 addresses checked and WRONG about the network - those 8 had been selected for the co-tenancy work, not as a sample. Checking all 85 announced /24 prefixes finds 191 reported addresses in a 30-day window, 68 of 85 prefixes with at least one, and 20 addresses at confidence >=75% of which 14 at 100% - worst 192.142.37.70 with 275 reports, 84.200.24.229 with 229, 159.100.19.157 with 116. Several sit in the AFRINIC space administered from a Gmail address and one (202.155.11.65, conf 97) in the IPXO-leased block. Published as its own section because the original was given prominence precisely for being inconvenient. OWNER SCREENING - a sourced negative replacing a bare assertion: ZERO matches for Doughouz, Doughous, Elin/Deen/Younes Doughouz, Ultahost, ScriptSun, WoWonder, Wolvor, Doughouz Group, PixelPhoto or DeepSound across the OFAC SDN list (19,250 rows retrieved), the OFAC consolidated list, the UK OFSI consolidated list (19,763 rows retrieved), SEC EDGAR full-text, and a widened CourtListener sweep. Both surname spellings were run because ICANN used 'Doughous'. ⚠TWO INDIVIDUAL QUERIES ERRORED and are recorded as NOT CHECKED rather than folded into 'no match': one SEC EDGAR term returned HTTP 500 and one CourtListener query was rate-limited at HTTP 429. ⚠The UK OFSI retrieval was originally left as a 404 'not checked' in the stored artifact while the site published a row count from a separate manual fetch - an adversarial check caught that the published figure had no traceable source, so the retrieval now runs in scripts/24-ofsi-screening.mjs and writes its own evidence. Also removed two weak sources the site had leaned on for personal claims - a commercial data broker (ZoomInfo) and an open user-editable wiki (EverybodyWiki) - and made remaining Crunchbase-only claims say so. The stale section heading 'Russian Birthplace', which survived Round 8's PII retraction, is also gone. RE-CHECKS: spx40k-fxempire.com still HTTP 200 with the same 184 KB clone on day 20, registry status still active, its 3 siblings still suspended; ICANN compliance index still one row, no action since the 23 Mar cure; broken-HTTPS moved the WRONG way, 12 of 32 sampled customer sites -> 14 (44%), with 2 more domains dead and nothing fixed. ⚠Sitejabber blocked every ladder tier including paid residential = NOT CHECKED. ⚠urlscan retrieval variance: a second pull returned 1,193 scans vs 1,400 the day before because the anonymous search serves a shifting window - the smaller number is NOT an improvement.
- Aug 24, 2026Sitejabber retrieved at last, and it changes two things. RETRIEVAL: this profile is Cloudflare-fronted and the scrape ladder fails on ALL 21 TIER ATTEMPTS - Firecrawl, render01, Webshare-DC, Crawl4AI, FlareSolverr, Camoufox, local FlareSolverr, local headed-Chrome, local Patchright, Webshare-GB, Webshare-ISP-UK, Camoufox+ISP-UK, paid IPRoyal residential and paid Camoufox+IPRoyal - every one returning a Cloudflare challenge, including the tiers running on our own residential connection. A PLAIN HTTP fetch from the same machine returns the real 621KB page first try and every try, with or without a User-Agent (3/3 verified). This Cloudflare configuration fingerprints browser AUTOMATION, so an ordinary HTTP client is less suspicious than a stealth browser. The site previously recorded Sitejabber as NOT CHECKED; it is now checked. NEW CONTENT: the profile is now branded SmartCustomer and carries a SECOND sentence this site had never quoted - the full notice reads 'Ultahost has been reported to offer discounts, coupons, or other compensation in exchange for reviews. This has been shown to lead to biased or misleading reviews.' The platform's own assessment, not ours. The same profile also states 'This company's rating is currently unavailable' - the score is suppressed - while the page title reads 'Ultahost Reviews - 13 Customers Rate 5.0/5 (2026)'. The profile is marked Claimed by the business. CORRECTION FOUND WHILE DOING THIS: the FAQ still asserted in the present tense that 'UltaHost operates TWO Trustpilot profiles' - a claim RETRACTED in Round 8 because the ultahost.io profile did not resolve on 4 August. That assertion has been replaced with what the platforms actually say today, including the fuller Sitejabber notice and the current bimodal Trustpilot split (64% five-star against 26% one-star, 10% across the middle three bands).
Verify the full picture
Our methodology page has a step-by-step walkthrough for verifying every major claim on this site in under 5 minutes. For the full chronological story, see the timeline.