Analysis as of August 01, 2026 indicates that the domain rr.twkohm.net remains active and is being leveraged in a phishing operation. The domain was registered on July 03, 2026 through IONOS SE and is hosted on IP address 217.160.255.171. Nameserver records point to ns1.pxymrg.info and ns2.pxymrg.info, which are commonly observed in malicious infrastructure.
Threat intelligence feeds have listed the domain on two security blocklists, and it is explicitly blocked by PhishDestroy and OpenPhish, confirming its association with phishing activity. VirusTotal scans show that six of ninety‑one security vendors flagged the domain, providing additional independent corroboration of malicious intent. No public information is available regarding the site’s SSL certificate, HTTP response codes, page title, or any brand targeting, leaving those aspects uncertain.
Defenders should prioritize network‑level blocks for the IP 217.160.255.171 and the domain rr.twkohm.net, update intrusion detection signatures to include the observed nameservers, and monitor outbound traffic for connections to the associated hosting infrastructure. Continuous re‑scanning with multi‑vendor services is advised to capture any changes in detection status, and any observed user reports should be escalated to incident response teams for rapid containment.