download-livedesktop.wixstudio.com is currently listed as an active generic phishing site under investigation. The domain resolves to the IPv4 address 162.159.143.12, which is hosted on infrastructure operated by Wix.com Ltd., the registrar for the sub‑domain. The DNS query for nameservers returns NS_NOT_FOUND, indicating that standard DNS records are not publicly exposed. The domain appears on a single security blocklist and is actively blocked by PhishDestroy, confirming that at least one reputable anti‑phishing feed has observed malicious activity associated with the host.
The limited public metadata suggests that the adversary is leveraging Wix’s free‑hosting platform to host a phishing landing page, a technique frequently observed in recent campaigns. No additional intelligence such as page title, SSL certificate details, or HTTP response codes is available at this time, leaving the exact content and delivery mechanism of the site unverified. Consequently, the precise lure, credential‑harvesting method, or targeted brand cannot be confirmed. Defenders should add the IP address 162.159.143.12 and the full domain name to block lists and network egress controls.
Monitoring for DNS queries to this domain and for outbound connections to the associated IP can help detect compromised clients attempting to reach the phishing host. Because the domain is hosted on a shared platform, any future sub‑domain created under the same Wix account may inherit the same malicious reputation; therefore, security teams should consider broader surveillance of the parent account when feasible. Continuous re‑evaluation is advised as additional data, such as HTTP headers or page content, becomes available.