xeno-plus[.]com
“bluyterm.com | 522: Connection timed out”
Evidence Summary
xeno-plus.com is assessed at elevated risk due to confirmed generic phishing activity. The domain was specifically flagged for attempts to harvest credentials or sensitive data from users. Current classification and threat intelligence indicate a strong likelihood of use in social engineering campaigns targeting unsuspecting visitors.
Technical analysis links xeno-plus.com to a registration date of June 23, 2026, via CNOBIN INFORMATION TECHNOLOGY LIMITED. The domain utilized an SSL certificate from Google Trust Services and resolved to IP address 104.21.64.237. VirusTotal reported 10 out of 95 security vendors flagging this domain as malicious. It is currently blocked by Hagezi and BLP-Malware and appears on two recognized security blocklists. The domain is currently offline, limiting immediate active risk.
Mitigation measures should include updating endpoint and gateway blocklists to prevent any future resolution or access to xeno-plus.com. Organizations should ensure user awareness training on phishing techniques and reinforce incident response protocols for credential-related phishing. All indicators of compromise, including the specific IP address, domain, and SSL details, should be integrated into monitoring and detection systems.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
2 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive