The domain humidifi-dex.net was registered on July 22, 2026 through Fewmoretaps OU d/b/a Trustname.com. Authoritative name servers listed for the zone are ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz and zeus.trustname.com, and DNS queries resolve the host to the IPv4 address 186.2.175.109. Public threat intelligence indicates that the domain appears on one security blocklist and is actively blocked by the PhishDestroy sinkhole service, confirming that at least one defensive platform has identified it as malicious. VirusTotal records reveal that 91 scanning engines have examined the domain; none have produced a detection result, which does not imply safety but shows a lack of current signatures.
The campaign has been labeled as generic phishing, and the investigative status is marked as under investigation while the domain remains active. No additional indicators such as SSL certificate details, HTTP status codes, page title, Safe Browsing entries, or Open Threat Exchange reports are present in the current intelligence set, leaving the surface‑level behavior of the web service uncharacterized. Consequently, the primary observable artifact is the domain name, its registration metadata, and the hosting IP address.
Defensive teams should consider adding humidifi-dex.net and the associated IP 186.2.175.109 to network deny lists, enforce DNS filtering, and monitor for any outbound connections to the address. Continuous re‑evaluation is advised, as future scans or blocklist updates may provide further context or detection signatures. Until more concrete payload or content analysis becomes available, the recommendation is to treat the domain as a high‑confidence phishing indicator based on its blocklist presence and attribution to a known malicious registrar.