Analysis of dex-saber.com, created on 22 July 2026 and hosted at IP 186.2.175.109, indicates that the domain is actively used in a generic phishing campaign. The registration record shows the domain was obtained through Fewmoretaps OU operating as Trustname.com, and the authoritative name servers listed are ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com. VirusTotal reports that the domain was examined by 91 AV engines, none of which returned a positive detection at the time of review.
The domain is presently listed on one external blocklist and is specifically blocked by the PhishDestroy service, confirming that threat‑intel feeds have identified it as malicious. No additional public intelligence such as OTX tags, Safe Browsing status, or SSL certificate details are available in the current dataset. Because the site remains reachable and the underlying IP has not been associated with known benign services, the infrastructure is considered suspicious.
Defenders should continue to block the domain at perimeter and DNS filtering layers, monitor the associated IP address for any changes in reputation, and consider adding the domain to internal blocklists. Ongoing observation is recommended to detect any evolution of the campaign, such as the appearance of new payloads or redirects, and to update incident response actions if further malicious activity is observed.