Analysis indicates that the domain app.fexowin.com is actively being used in a phishing operation as of the report date, July 28 2026. The domain was registered only five days earlier on July 23 2026 through Fewmoretaps OU d/b/a Trustname.com, suggesting a rapid deployment typical of opportunistic campaigns. Infrastructure examination shows the domain resolves to the IP address 64.7.198.11 and is served by Cloudflare nameservers chase.ns.cloudflare.com and pola.ns.cloudflare.com, meaning the attacker is leveraging Cloudflare’s CDN and DNS services to obscure the true origin of the traffic.
VirusTotal has recorded 13 of 91 security vendors flagging the domain, providing modest but notable consensus among detection engines that the site is malicious. The domain appears on a single security blocklist and is explicitly listed by the PhishDestroy blocklist, confirming that at least one external threat‑intelligence source has taken remediation action. No public Safe Browsing, OTX, SSL, HTTP status, or page‑title information is currently available, leaving those vectors unverified.
Defenders should immediately add app.fexowin.com to outbound and inbound filtering rules, monitor DNS queries for the associated IP, and consider sinkholing the domain to disrupt the campaign. Continuous re‑evaluation is advised, as additional detection signatures or blocklist entries may emerge as the threat actor’s infrastructure evolves.