Analysis of sonixhub.xyz indicates a high‑risk phishing infrastructure that remains active as of the report date, July 30, 2026. The domain resolves to the IPv4 address 102.129.165.167 and is hosted under the Ultahost, Inc. registrar. Registration metadata show the domain was created on July 03, 2026 and is serviced by four authoritative name servers – ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, and ns4.ultahost.com – all belonging to the same provider. Threat‑intel feeds have flagged the domain on one security blocklist, and the anti‑phishing platform PhishDestroy has actively blocked it, confirming that defensive controls are already in place against this indicator.
VirusTotal scans reveal that three of ninety‑one submitted security engines have generated detections for the domain, providing independent corroboration of malicious intent. No additional public observations such as Safe Browsing status, OTX tags, or SSL certificate details are available, leaving the precise payload or lure used by the site unverified. The limited detection count suggests that the phishing kit may be employing techniques that evade many scanners, or that the domain has been recently deployed and thus has low coverage.
Defenders should prioritize adding 102.129.165.167 to network‑level blocklists, enforce DNS filtering for sonixhub.xyz, and monitor any outbound connections to the associated name servers. Continuous re‑scanning of the domain on VirusTotal and other sandbox services is recommended to capture evolving payloads. Incident response teams should treat any credential submissions or traffic to this domain as compromised and initiate credential rotation and user awareness notifications.