On July 29, 2026, the domain apps-trxosuites.wixstudio.com was identified as a generic phishing infrastructure and placed under active investigation. The domain is registered through Wix.com Ltd., a well‑known website‑building platform, and remains active at the time of analysis. DNS resolution points to the IP address 162.159.143.12, which is hosted by a cloud service provider commonly used by legitimate Wix sites. The TLS certificate presented by the server is issued by Let’s Encrypt (YR1), indicating that the site is capable of serving HTTPS traffic.
Nameserver information could not be retrieved, as the query returned NS_NOT_FOUND. The domain has been blocked by the security vendor PhishDestroy and appears on a single security blocklist, confirming that at least one external organization has flagged the host as malicious. No additional public blocklists or safe‑browsing feeds currently list the domain, and no further intelligence such as page titles, brand impersonation details, or malware kits has been published.
Given the limited available evidence, the primary indicators of compromise are the registrar (Wix.com Ltd.), the hosting IP (162.159.143.12), the active block by PhishDestroy, and the presence on one blocklist. Defenders should consider adding the domain and its resolved IP address to outbound filtering rules, monitor DNS queries for the domain, and employ SSL inspection to verify the Let’s Encrypt certificate fingerprint if possible. Continued observation is recommended to detect any evolution of the payload or emergence of additional artifacts, such as page content or credential‑stealing forms, which have not yet been disclosed.