The domain user.financexaufx.com was registered through Gransy, s.r.o. on June 20, 2026 and is currently active. DNS resolution points to IP address 104.21.84.176, an address associated with Cloudflare's edge network, and the authoritative name servers are leah.ns.cloudflare.com and rommy.ns.cloudflare.com. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, indicating that threat intelligence sources have already flagged it as malicious.
VirusTotal records show that the domain was scanned by 91 antivirus engines, none of which reported a detection at the time of analysis; this lack of detections does not constitute evidence of safety. No public SSL certificate details, HTTP status codes, or page title information are presently available, limiting insight into the site’s content and behavior. The short lifespan of the domain combined with its immediate presence on a phishing‑focused blocklist suggests a deliberate deployment for credential‑harvesting or related fraud.
Defenders should add the domain to network and endpoint deny lists, enforce DNS filtering using reputable phishing feeds, and monitor traffic to the associated IP for anomalous patterns. Ongoing re‑scanning with multi‑engine services is recommended to capture any future malicious payloads that may be introduced. Based on the observable infrastructure and blocklist activity, the domain should be treated as a high‑confidence phishing indicator while further forensic analysis is conducted.