Analysis of sui-dex.xyz indicates an active malicious infrastructure supporting a generic phishing operation. The domain resolves to the IPv4 address 186.2.175.35 and was created on July 02, 2026 through the registrar NameSilo, LLC. Its authoritative name servers—ns1.dnsowl.com, ns2.dnsowl.com and ns3.dnsowl.com—are frequently observed in other abuse‑related deployments, suggesting purposeful configuration for short‑lived malicious use. VirusTotal records show that 2 of 91 security vendors have flagged the host, providing independent confirmation that the domain is associated with malicious activity.
The site is presently listed on a public phishing blocklist and is explicitly blocked by the PhishDestroy service, further evidencing that defensive communities have identified abusive behavior tied to this host. No page title, SSL certificate details, HTTP status codes, or content snapshots are included in the current intelligence, leaving the exact visual or credential‑capture mechanisms unverified. Nonetheless, the convergence of a recent registration, dedicated DNS infrastructure, vendor detections, and blocklist inclusion establishes a high‑confidence indication of phishing intent, justifying the assigned high‑risk rating.
Defensive recommendations include adding sui-dex.xyz and its IP address 186.2.175.35 to DNS and network filtering rules, monitoring for DNS queries and outbound connections to the host, and considering sinkholing or sinkhole redirection to disrupt future campaign activity. Organizations should also share these indicators with regional and industry‑wide threat‑intel platforms to improve collective detection, and conduct periodic re‑assessment in case additional artifacts such as page content, malware payloads, or command‑and‑control infrastructure become available.