Analysis of sessor349.com indicates a recently established phishing domain with active malicious infrastructure. The domain was registered on July 27, 2026, through Dominet (HK) Limited, a registrar frequently associated with high-risk domains. It currently resolves to IP address 91.92.241.145 and is served by Cloudflare nameservers (kenia.ns.cloudflare.com, plato.ns.cloudflare.com), a configuration commonly observed in phishing campaigns to obscure hosting origins and evade takedowns.
As of July 31, 2026, the domain remains active and is flagged by one security blocklist, specifically PhishDestroy. VirusTotal detection data shows minimal coverage, with only 2 out of 91 security vendors identifying the domain as malicious, suggesting either limited exposure or effective evasion techniques. No additional context regarding the phishing target, specific brand impersonation, or page content is available in the current intelligence.
Defenders are advised to treat this domain as high-risk and implement blocking at the DNS or network level. Monitoring for changes in detection status, resolving IP, or additional blocklist inclusions is recommended, as the domain may represent an early-stage phishing operation with evolving infrastructure.