Analysis of sessor359.com indicates an active phishing domain registered on July 27, 2026, through Dominet (HK) Limited. The domain currently resolves to IP address 91.92.241.145 and uses Cloudflare nameservers (chad.ns.cloudflare.com, norah.ns.cloudflare.com). As of July 31, 2026, two of ninety-one security vendors on VirusTotal flag this domain as malicious.
It appears on one security blocklist and is blocked by PhishDestroy. No brand target or specific phishing kit is confirmed in available intelligence; the site content remains unanalyzed beyond its classification as a generic phishing domain. Defenders should treat this domain as high-risk infrastructure.
Recommended actions include adding the domain and its resolving IP to web gateways, email filters, and endpoint protection rules. Monitor for new detections or blocklist additions, as the domain is less than five days old and may still be evolving. If internal telemetry shows connections to 91.92.241.145, investigate for credential theft or malware delivery attempts.