Analysis as of July 29, 2026 indicates that the domain trexor-io.wixstudio.com is actively being used in a credential harvesting campaign. The domain is registered through Wix.com Ltd., a popular website‑building service, and resolves to the IPv4 address 162.159.143.12. DNS queries returned no name‑server records (NS_NOT_FOUND), suggesting that the authoritative nameservers are not publicly disclosed. The site presents a valid TLS certificate issued by Let’s Encrypt (certificate label YR1), confirming that HTTPS connections are encrypted but offering no assurance about the legitimacy of the hosted content.
VirusTotal has processed the domain with 91 scanning engines; at the time of this review none of those engines reported a detection. This absence of alerts should not be interpreted as an indication of safety, as automated scanners may miss novel or manually‑crafted phishing payloads. The domain is currently listed on a single security blocklist and has been explicitly blocked by the PhishDestroy filtering service, reinforcing the likelihood of malicious use.
No public Safe Browsing, Open Threat Exchange, or page‑title information is available for this host, and no additional intelligence such as brand targeting or phishing kit attribution has been disclosed. Consequently, the precise luring technique and victim profile remain uncertain. Defenders should treat trexor-io.wixstudio.com as a high‑confidence indicator of phishing activity. Recommended actions include adding the domain to organizational blocklists, monitoring outbound connections to the associated IP address, and employing URL filtering solutions that reference the current blocklist entry. Continuous re‑evaluation is advised, as threat actors may modify the site or shift hosting infrastructure without notice.