This investigation documents the current threat posture of the domain coincomms.xyz. The domain was registered on 25 July 2026 through Global Domain Group LLC and is hosted on the IP address 63.176.8.218. All four authoritative nameservers resolve to the nsone.net network (dns1.p01.nsone.net through dns4.p01.nsone.net), indicating the use of a commercial DNS provider. As of 1 August 2026 the domain remains active and is listed on two independent phishing blocklists, PhishDestroy and ScamSniffer, confirming that it has been observed in malicious campaigns.
VirusTotal reports that the domain was scanned by 91 antivirus and URL‑reputation engines; none of the engines raised a detection at the time of analysis, which does not imply the absence of malicious content. No public Safe Browsing, Open Threat Exchange, SSL certificate, HTTP response code, trust‑score, or page‑title information is presently available for coincomms.xyz, limiting the depth of technical fingerprinting. The evidence therefore points to a newly created, actively hosted infrastructure that is already being used for generic phishing activity, but the exact payload, targeted brands, or victim interaction flow have not been disclosed.
Defenders should add coincomms.xyz to internal blocklists, monitor DNS queries for the nsone.net name servers, and enforce outbound filtering for connections to the IP 63.176.8.218. Continuous re‑scanning with URL‑reputation services is recommended, as the lack of detections may change rapidly. Network and email security teams should also consider correlating any user‑reported phishing attempts with the observed blocklist entries to improve detection coverage.