On July 29, 2026 the domain io-exods-wlt-sanni.wasmer.app was observed as an active generic phishing infrastructure. VirusTotal records indicate that nine out of ninety‑one scanning engines have issued a detection for the domain, confirming malicious intent. The domain is registered through Wasmer Inc. and resolves to the IPv4 address 62.210.172.150.
Authoritative name servers alpha.ns.wasmernet.com and beta.ns.wasmernet.com are listed, suggesting the hosting provider is the same entity that supplied the registration service. The domain appears on a single external security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, demonstrating that at least one downstream protection system has recognised and mitigated the threat. No additional public intelligence such as Safe Browsing verdicts, OTX references, or SSL certificate details are currently available, leaving the broader attribution and payload characteristics uncertain.
Defenders should add the domain and its resolving IP to block lists at the network perimeter, update DNS filtering policies to deny queries for the domain, and monitor for any outbound connections to the IP address. Continuous re‑evaluation is advised, as the threat actor may alter hosting or employ additional domains. Given the high risk rating and the observed detection rate, organizations handling credential‑sensitive workflows should treat any communications originating from this domain as malicious and enforce strict verification procedures.