The domain updatextraconzsecure.weebly.com is actively being used for credential phishing as of the report date 30 July 2026. Infrastructure analysis shows that the domain resolves to the IPv4 address 74.115.51.8. The hosting provider associated with this address is not explicitly listed, but the IP is publicly routable and does not belong to a known content‑delivery network. The domain’s registrar information indicates it was registered through Square, Inc., a commercial registration service, suggesting the registrant leveraged a popular platform to obtain the sub‑domain. No authoritative name server records could be retrieved; attempts to query NS records returned NS_NOT_FOUND, which may indicate either a misconfiguration or deliberate obfuscation of the DNS infrastructure.
Threat intelligence feeds have flagged the domain on two public blocklists. Both PhishDestroy and OpenPhish enumerate the domain as a confirmed phishing source, reinforcing the high‑risk assessment. VirusTotal analysis shows that 14 of 91 scanning engines flagged the domain as malicious, providing additional corroboration from multiple vendors. The domain appears on no additional blocklists in the supplied data, and there is no evidence of SSL/TLS deployment; the lack of HTTPS suggests the site may rely on plain HTTP, a common characteristic of credential‑harvesting pages. While the page title, HTTP response codes, and any observed branding are not available in the current intelligence set, the combination of blocklist presence, registrar choice, IP resolution, and multi‑vendor detections establish a clear pattern of malicious activity.
The absence of name server details and the lack of a reported SSL certificate constitute uncertainties that warrant further active probing by security teams. Defenders should immediately block traffic to updatextraconzsecure.weebly.com at the network perimeter and add the associated IP address 74.115.51.8 to deny‑lists.