The domain rhinofi-dex.net was registered by Fewmoretaps OU doing business as Trustname.com on 30 July 2026. It is currently active and resolves to the IPv4 address 186.2.175.35. The authoritative name servers listed for the zone are ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz and zeus.trustname.com. VirusTotal records show that scans have been performed by 91 independent scanners, with none reporting a detection at the time of analysis; this absence of detections does not constitute a safety assurance.
The domain is present on a single external security blocklist and is explicitly blocked by the PhishDestroy service, indicating that at least one security vendor has classified it as malicious. No public information about SSL certificates, HTTP response codes, page titles, or targeted brands is available in the current intelligence set, so the exact content and phishing vector remain unconfirmed. Infrastructure analysis therefore relies on registration, DNS, and blocklist data. Defenders should immediately add rhinofi-dex.net and its resolving IP 186.2.175.35 to network‑level deny lists and endpoint protection rules.
Continuous monitoring of the domain’s DNS records is advised to detect any changes to name servers or additional IP addresses. Because the domain is already flagged by PhishDestroy, integrating its feed into existing threat‑intel platforms will provide early warning for future campaigns that reuse the same registrar or hosting infrastructure. Organizations that employ web‑proxy or secure‑web‑gateway solutions should ensure that requests to this domain are blocked, and security teams should consider correlating internal logs for any sightings of the IP address to identify possible compromised endpoints. Until further forensic analysis of the site’s payload is obtained, the domain should be treated as a confirmed phishing resource and mitigated accordingly.