Analysis of zesowin.com reveals a recently established domain exhibiting multiple indicators consistent with credential-theft phishing infrastructure. The domain was registered on July 24, 2026, through Fewmoretaps OU operating as Trustname.com, a registrar frequently associated with short-lived phishing campaigns. As of July 28, 2026, the domain remains active and resolves to the IP address 154.86.119.65, which has previously hosted other domains flagged for phishing activity.
Security vendor detections on VirusTotal show 16 of 91 engines marking the domain as malicious, while PhishDestroy has explicitly blocked it, confirming its presence on at least one high-confidence blocklist. The nameservers— a.dnspod.com, b.dnspod.com, and c.dnspod.com—are part of DNSPod’s infrastructure, commonly used by threat actors to rapidly deploy and rotate phishing sites. No specific brand target or page content has been confirmed in available intelligence, so the exact nature of the login portal or service being impersonated remains unconfirmed.
However, the combination of a newly registered domain, active resolution, multiple security detections, and association with known phishing-supportive infrastructure strongly indicates a high-risk credential harvesting operation. Defenders are advised to block the domain at DNS and proxy levels, monitor for connections to 154.86.119.65, and review logs for user access attempts to zesowin.com. Further analysis of HTTP headers, SSL certificates, and page content is recommended to determine the targeted brand and refine detection rules.