Analysis as of July 29, 2026 indicates that the domain app-jtx.trade remains active and is being leveraged in a generic phishing operation. DNS resolution points to the IP address 172.67.179.90, which is owned by Cloudflare, as confirmed by the authoritative name servers kianchau.ns.cloudflare.com and zita.ns.cloudflare.com. The domain is listed on one external security blocklist and has been explicitly blocked by the PhishDestroy filtering service, demonstrating that some security products have already taken mitigation steps.
VirusTotal scans show that 2 of 91 security vendors have flagged the domain, providing additional confirmation of malicious intent. No public evidence of the site’s page title, SSL certificate details, HTTP response codes, or brand targeting has been disclosed, leaving the exact content and phishing lure unknown.
Consequently, defenders should treat the domain as high risk, enforce DNS or proxy level blocking, and monitor for any new indicators such as additional vendor detections or blocklist listings. Ongoing observation of Cloudflare‑associated IP activity and periodic re‑scans with VirusTotal or similar aggregators are recommended to capture any changes in the threat posture.