Analysis as of July 30 2026 identifies the newly registered domain suazox.com as part of an active generic phishing campaign. The domain was created on July 25 2026 and is registered through Fewmoretaps OU d/b/a Trustname.com. It resolves to the IPv4 address 188.114.97.3, which is hosted behind Cloudflare nameservers addilyn.ns.cloudflare.com and jaime.ns.cloudflare.com. The infrastructure has been observed on a single public blocklist and is currently blocked by the PhishDestroy service, indicating that at least one sink‑hole or mitigation platform has flagged the host.
VirusTotal records show the domain was scanned by 91 antivirus and URL‑reputation vendors, none of which raised a detection at the time of the scan; the absence of a detection does not constitute evidence of legitimacy. No additional metadata such as SSL certificate details, HTTP response codes, page title, or targeted brand information is presently available, limiting the ability to confirm the exact phishing payload or lure employed. Consequently, the precise impersonated service remains uncertain.
Defenders should treat suazox.com as a high‑confidence malicious indicator: block the domain at the DNS and proxy layers, add the associated IP address 188.114.97.3 to network‑wide deny lists, and monitor for any outbound connections or credential submissions to the host. Continuous re‑evaluation is recommended as further intelligence, such as content analysis or additional blocklist appearances, becomes available. Organizations using threat‑intelligence platforms should ingest the registrar and hosting details to enrich correlation rules and improve early detection of related campaigns.