Hi Denis S.

The main domain may be a legit and registered website on a dedicated server in Hong-Kong, see: http://whois.domaintools.com/xgphuhxhitxjtdxery.net
The sub domains may not be and could have been specifically crafted for malicious purposes.
See also Peter Kleissner’s data on the main IP: https://virustracker.net/103.240.82.138
When malicious per se Peter always adds “criminal” there, meaning there is active and up malcode, no more no less.
The AS is not malicious per se with only 14 bad & blacklisted URLs: http://sitevet.com/db/asn/AS9919

polonus

P.S. As you see I have changed the topic wordings to better reflect the intention of your reaction :wink: