Analysis indicates that coinhall-dex.com was registered on July 22, 2026 through Fewmoretaps OU d/b/a Trustname.com. The domain resolves to the IPv4 address 186.2.175.109 and is served by the nameservers ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz. VirusTotal reports that five of ninety‑one scanned security vendors flag the domain as malicious, confirming a detection signal from multiple independent sources. The domain appears on a single public security blocklist and is actively blocked by the PhishDestroy service, confirming that at least one anti‑phishing platform has taken remediation action.
No additional public intelligence such as SSL certificate details, HTTP response codes, or page title information is currently available, limiting visibility into the exact payload or credential‑harvesting technique employed. The short interval between registration and detection suggests a rapid deployment of a phishing campaign, potentially targeting cryptocurrency users given the “coinhall” lexical component, though the specific lure remains unverified. Uncertainty remains regarding the underlying hosting provider, any affiliated command‑and‑control infrastructure, and whether the domain is part of a larger multiplex of similar‑named domains. Defenders should immediately add 186.2.175.109 to network‑level deny lists and configure DNS filtering to block coinhall-dex.com across enterprise resolvers.
Monitoring of outbound connections to the identified IP and the associated nameservers is advised to detect any attempted exfiltration. Security teams should also incorporate the five VirusTotal vendor detections into their SIEM correlation rules to raise alerts on any future sightings of the domain or its IP. Continuous re‑evaluation is recommended as additional threat intelligence, such as page content or observed victim reports, becomes available.