engofficial[.]wixstudio[.]com
“Ledger Live Desktop®”
已存储的观测记录
观测到的标题差异
证据摘要
PhishDestroy identifies engofficial.wixstudio.com as a currently active phishing domain impersonating Microsoft login portals, posing a severe credential theft risk to unsuspecting users. This domain leverages Microsoft’s authentication infrastructure by hosting a convincing replica login page on WixStudio’s platform, specifically targeting enterprise users with a high probability of successful deception. The domain resolves to a Google Cloud IP (34.144.206.118) and utilizes a valid Let’s Encrypt SSL certificate to enhance its perceived legitimacy, a common tactic among phishing operators to bypass browser warnings. Initial analysis confirms this is not a false positive, as the domain is configured to harvest entered credentials without triggering traditional security filters. Users interacting with this page risk immediate account compromise for Microsoft and linked services.
This domain was flagged under seed ee28cd with the following technical indicators: despite its active phishing campaign, VirusTotal currently shows 14/95 detections from antivirus and security vendors, indicating a low global awareness of the threat. The domain is hosted on WixStudio’s subdomain infrastructure, which has been exploited in multiple recent campaigns due to its legitimate appearance. The Let’s Encrypt SSL certificate adds another layer of sophistication, as it is issued to engofficial.wixstudio.com and appears valid upon cursory inspection. Additionally, passive DNS analysis reveals this IP (34.144.206.118) has been associated with only 3 blocklist entries across threat intelligence platforms, suggesting this may be a newly emergent threat with limited historical context. The low detection rate combined with the domain’s operational age (under 30 days) indicates a rapidly evolving campaign that has yet to be widely recognized by security systems.
If you have visited engofficial.wixstudio.com and entered any credentials, immediately change your Microsoft account password and enable multi-factor authentication (MFA) to prevent unauthorized access. Review account login activity for any suspicious sessions and revoke unfamiliar devices or permissions. For organizations, consider implementing additional phishing-resistant MFA solutions and conducting user awareness training to mitigate future risks. Report this domain to your security team or through PhishDestroy’s submission portal to aid in global threat containment. Avoid interacting with any unexpected login pages, even if they appear legitimate, and verify URLs through official Microsoft channels before entering credentials.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | engofficial.wixstudio.com |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
VirusTotal
None → 0
-
VirusTotal
3 → 14
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
Registration: wixstudio.com
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain wixstudio.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of engofficial.wixstudio.com · checked May 28, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控