coredex[.]space
“The Decentralized Protocol”
On 22 July 2026, coredex.space was identified as an active generic‑phishing infrastructure with a high risk rating. The domain was created on 25 June 2026 and resolves to the IPv4 address 88.222.222.156, which is allocated to Hostinger International Ltd. in Lithuania. Hosting metadata shows the site is served through Hostinger’s CDN and advertises HTTP/3 support, but it lacks an SSL/TLS certificate, meaning all traffic is unencrypted. The authoritative name servers are ns1.dns-parking.com and ns2.dns-parking.com, both typical of parked or rapidly provisioned domains.
The page title returned by the web server is "The Decentralized Protocol", a generic phrase that offers no indication of legitimate purpose. The domain appears on four independent blocklists—PhishDestroy, MetaMask, ScamSniffer, and SEAL—each of which classifies it as malicious. VirusTotal records show the site has been scanned by 91 antivirus engines without a detection, but the absence of a detection does not imply safety, especially given the blocklist presence and phishing classification. The registrar information lists HOSTINGER operations, UAB as the registering entity, consistent with the hosting provider.
No additional indicators such as known malware kits, brand impersonation, or specific phishing pages have been publicly disclosed. Given the combination of a newly registered domain, lack of encryption, placement on multiple blocklists, and the generic page title, defenders should treat coredex.space as hostile. Recommended mitigations include adding the domain to network deny lists, monitoring DNS queries for the associated IP and name servers, and employing web-filtering solutions that reference the listed blocklists. Continuous re‑evaluation is advised in case new payloads or credential‑stealing pages appear.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
Hostinger is an employee-owned Web hosting provider and internet domain registrar.
www.hostinger.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of coredex.space · checked Jul 19, 2026
Evidence & External Reports
PD-20260719-A35F7E Recipient: abuse@hostinger.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive