I can see many similar domains and subdomains being used at the moment:

https://urlquery.net/report.php?id=1438638521403
http://urlquery.net/report.php?id=1438668093830

And their URL patters look very malicious.

Moreover some of them (e.g. hxxp://4d2j[.]fsmrpjzrzkiu[.]com/) Google already flags as Phishing

P.S. I used this Google query: [site:urlquery.net xgphuhxhitxjtdxery.net]
https://www.google.com/search?q=site:urlquery.net+xgphuhxhitxjtdxery.net