Analysis of attmicapp-home.wixstudio.com shows that the domain actively resolves to the IP address 162.159.143.12. The hosting IP is part of the Cloudflare network frequently employed by Wix‑hosted sites, indicating that the domain leverages Wix.com Ltd. as its registrar and underlying platform. The TLS certificate presented by the site is issued by Let’s Encrypt under the YR1 identifier, confirming that the connection is encrypted but offering no assurance of legitimacy.
DNS queries return a non‑existent nameserver record (NS_NOT_FOUND), limiting further zone‑level investigation and suggesting that the authoritative name servers are either hidden or not publicly resolvable. The domain is currently listed on a single security blocklist and has been explicitly flagged by the PhishDestroy mitigation service, reinforcing the assessment that it is being used for malicious phishing activity. No additional intelligence such as page titles, HTTP response codes, or content hashes is available, leaving the precise phishing payload and targeted brand undefined.
Defenders should immediately add attmicapp-home.wixstudio.com to URL and DNS blocklists, enforce TLS inspection where feasible, and monitor for any changes to the domain’s DNS configuration or certificate issuance. Continuous observation of the associated IP address for new hostings or related domains is advised, as the shared Cloudflare infrastructure can host multiple malicious sites. Until further content analysis is performed, the domain remains classified as an active phishing threat.