zuytyarws[.]xin
“à¤à¤° दà¤à¤¡ सà¥à¤à¤¨à¤¾ - à¤à¤¾à¤°à¤¤ सरà¤à¤¾à¤°”
Evidence Summary
Analysis of zuytyarws.xin indicates a high-risk phishing domain active as of August 2, 2026. The domain was registered on July 19, 2026, through GNAME.COM PTE. LTD., a registrar frequently associated with newly created fraudulent sites. Infrastructure analysis reveals hosting in Hong Kong under Apex Speed LTD, resolving to IP 103.23.172.15. The nameservers—including a.share-dns.com, a1.share-dns.com, b.share-dns.net, and b1.share-dns.net—are commonly used by threat actors to rapidly deploy and rotate malicious domains.
SSL certification from Let's Encrypt is present, a tactic often employed to lend superficial legitimacy to phishing pages, though it provides no assurance of safety. Detection data further supports malicious classification: the domain appears in five AlienVault OTX threat intelligence pulses and is flagged by 8 of 91 security vendors on VirusTotal. It is also listed on at least one security blocklist and blocked by PhishDestroy. Trust scores from Gridinsoft (1/100) and Scamadviser (15/100) reinforce the high-risk assessment. The site employs Nginx as a web server and supports HSTS and HTTP/3, technologies sometimes used to evade basic detection but not inherently malicious on their own.
No specific brand target or phishing kit has been confirmed in available data, and the exact content of the site remains unanalyzed. However, the combination of recent registration, low-reputation hosting, shared malicious infrastructure, and multiple vendor detections strongly suggests this is an active credential-harvesting or fake login scam. Defenders should treat the domain as compromised and block resolution at the DNS level. Users encountering this domain should avoid interaction, and organizations should monitor for connections to 103.23.172.15 in network logs as a potential indicator of compromise.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260802-DBB38E- PDF artifact
- PDF evidence
Full evidence text
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | zuytyarws.xin |
phishing | Phishing Block |
| DNS4EU | zuytyarws.xin |
malicious | Sinkholed |
| Cloudflare DNS | zuytyarws.xin |
malicious | Sinkholed |
| DigiCert UltraDNS | zuytyarws.xin |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
-
Domain status
Reachable → Unreachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of zuytyarws.xin · checked Aug 2, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive