The domain myssoappsuitecdn.wixstudio.com is currently active and resolves to the IPv4 address 162.159.143.12. Registration information shows the domain was created through Wix.com Ltd., a legitimate website‑builder service, and the domain is protected by a Let’s Encrypt certificate that was issued for a one‑year validity period (YR1). The DNS record for the authoritative nameservers is listed as NS_NOT_FOUND, indicating that standard name‑server queries do not return a usable set of name‑servers for the domain.
Security telemetry indicates that the domain is listed on a single blocklist and has been explicitly blocked by the PhishDestroy mitigation service. The presence on a blocklist, combined with the generic phishing classification supplied in the intelligence brief, suggests the domain is being used for malicious credential‑harvesting activity, although no public page content, HTTP response codes, or payload samples have been shared. Defenders should treat the domain as suspicious pending further investigation.
Immediate actions include adding the host to outbound and inbound URL filtering rules, enforcing TLS inspection to capture any encrypted traffic, and monitoring DNS queries for the resolved IP address. Because the domain resides on a shared hosting platform associated with Wix, blocking the entire hosting range may cause collateral impact; therefore, granular blocking of the specific hostname is preferred. Continuous re‑evaluation is recommended as additional indicators, such as HTTP response analysis, client‑side telemetry, or new blocklist entries, become available.