The domain lockerfn.xyz was registered on June 22, 2026 through Global Domain Group LLC and is currently using the DNS service a.dnspod.com, b.dnspod.com, and c.dnspod.com. DNS resolution points to the IPv4 address 158.94.211.169, indicating that the site is hosted on a single host without additional load‑balancing infrastructure. VirusTotal reports that one out of ninety‑one scanned security vendors flagged the domain, suggesting limited detection coverage but confirming malicious intent.
The domain is listed on a single public blocklist and is actively blocked by the PhishDestroy mitigation platform, confirming that defensive services have identified it as a threat. The domain’s status is marked as active, meaning the phishing infrastructure remains reachable. Observed evidence is limited to registration metadata, name server configuration, IP address, and the single vendor detection; no public page title, SSL certificate details, or content analysis have been disclosed.
Consequently, the precise phishing lure or targeted brand cannot be determined from the available data. Defenders should add lockerfn.xyz to network‑level deny lists, update DNS filtering services, and monitor outbound connections to 158.94.211.169 for potential data exfiltration. Continuous re‑evaluation is advised, as additional detection signals may emerge as more security vendors scan the domain.