zxizusuy[.]xin
Analysis of the domain zxizusuy.xin indicates that it is actively being used for credential harvesting. VirusTotal scans have returned detections from 11 of 91 security vendors, signaling that multiple independent tools have observed malicious behavior associated with the domain. The domain is listed on a single security blocklist and is explicitly blocked by the PhishDestroy mitigation service, confirming that at least one operational blocklist has deemed the host to be malicious.
No additional intelligence such as registrar details, hosting IP, ASN, or SSL certificate information has been published, leaving the underlying infrastructure opaque. The lack of public page title or brand targeting data means that the exact phishing lure—whether it impersonates a financial institution, service provider, or other entity—cannot be confirmed at this time. Defenders should prioritize adding zxizusuy.xin to DNS and URL filtering policies, especially in environments that rely on automated blocklists, to prevent user exposure.
Continuous monitoring of threat intelligence feeds for any emergence of related indicators, such as IP address allocations or hosting changes, is recommended. Organizations with credential‑based authentication should enforce multi‑factor authentication and monitor for anomalous login attempts that could be linked to this domain. The current evidence set supports a proactive defensive posture, but further investigation is required to fully map the campaign’s scope and infrastructure.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive