fimy[.]xyz
“fimy.xyz”
The domain fimy.xyz is currently classified as a high‑risk generic phishing site. According to the latest intelligence collected on July 26, 2026, the domain is listed on one security blocklist and has been flagged by one of ninety‑one VirusTotal‑registered security vendors. PhishDestroy has actively blocked the domain, indicating it is recognized by at least one dedicated anti‑phishing service. Registration data shows the domain was created through CommuniGal Communication Ltd., and the authoritative name servers are ns15.abovedomains.com and ns16.abovedomains.com.
An HTTP request to the root URL returns a 200 OK status, confirming that the web service is reachable and operational. No additional details about the page content, SSL certificate, or hosting infrastructure have been released, so the exact phishing vector and targeted brand remain unknown. The presence of a positive detection on VirusTotal and the inclusion on a blocklist suggest a non‑trivial threat, but the limited number of detections indicates that the malicious infrastructure may be newly deployed or employing evasion techniques that evade broader detection. Defenders should add fimy.xyz to inbound and outbound filtering rules, monitor DNS queries for the domain and its authoritative name servers, and consider employing URL‑reputation services that reference the blocklist entry.
Since the site is actively serving content (HTTP 200), any attempted connections should be terminated or redirected to a safe browsing page. Continuous re‑scanning of the domain on multi‑vendor platforms is advised to capture any changes in detection status. Further analysis is required to determine the specific credential‑stealing tactics, any associated command‑and‑control hosts, and whether the domain is part of a larger phishing campaign. Until such data become available, the recommendation is to treat fimy.xyz as malicious and block it across enterprise perimeter defenses.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of fimy.xyz · checked Jul 26, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive