Analysis of deriverse-dex.net shows an active generic phishing infrastructure that was created on July 22, 2026. The domain is registered through Fewmoretaps OU doing business as Trustname.com and is served by four nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com. DNS resolution points to the IPv4 address 186.2.175.109, which is the sole host observed for this domain.
On VirusTotal the domain was submitted to 91 antivirus and URL scanning engines, none of which raised a detection; the report explicitly notes that the lack of detections does not constitute a safety guarantee. The domain is currently listed on one security blocklist and has been flagged by the PhishDestroy service, indicating that at least one external threat‑intel feed considers it malicious. No additional telemetry such as SSL certificate details, HTTP response codes, page titles, or brand targeting information is available at this time, leaving the exact phishing payload and victim lure unknown.
Given the recent creation date, active status, and confirmed presence on a blocklist, defenders should treat deriverse-dex.net as a high‑confidence phishing indicator. Recommended mitigations include adding the domain and its resolving IP address to network deny lists, monitoring DNS queries for the associated nameservers, and employing URL filtering solutions to block access. Continuous re‑scanning on multi‑engine platforms is advised to capture any future payload changes, and any observed traffic should be logged for further forensic correlation.