# axocode.vip — SUSPICIOUS > axocode.vip is a newly registered fake invoice phishing domain. Flagged by 0 of 95 VirusTotal vendors. Check the full report. ## Summary PhishDestroy identifies axocode.vip as an active invoice-themed phishing domain currently under investigation for impersonation tactics. The domain exhibits high-risk indicators consistent with financial fraud targeting businesses through fraudulent billing schemes. Current evidence suggests it leverages urgency-based lures, such as fake overdue invoices, to trick users into disclosing payment credentials or downloading malware. The threat remains unclassified by security vendors but shows clear alignment with evolving invoice scam infrastructures. This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating it has evaded detection by major antivirus engines. Registered through Global Domain Group LLC, axocode.vip resolves to IP 209.112.89.200 and holds a valid Let's Encrypt SSL certificate. The domain was created on March 19, 2026, making it less than one month old—an early-stage red flag commonly exploited by fast-flux phishing operations. With no current blocklist presence and no established trust scores, this domain presents a high operational risk to unsuspecting users and organizations. In response to these findings, PhishDestroy recommends immediate network-level blocking of axocode.vip and its associated IP (209.112.89.200) via DNS sinkholing or firewall rules. Due to the domain's recent creation and low detection rate, users should treat any emails referencing axocode.vip as malicious and avoid clicking embedded links or opening attachments. Organizations are advised to update email filtering rules to quarantine messages containing invoice-themed lures with stress on urgency. Continuous monitoring of this domain is ongoing, and security teams are encouraged to report any sightings to threat intelligence platforms for collaborative defense. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-19 13:17:13 - Registrar: Global Domain Group LLC - IP: 209.112.89.200 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/axocode.vip - PhishDestroy: https://phishdestroy.io/domain/axocode.vip/ - LLM endpoint: https://phishdestroy.io/domain/axocode.vip/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/axocode.vip/ Last updated: 2026-04-05