Analysis of app.meopex.com as of August 01, 2026 confirms it as an active phishing domain with high-risk indicators. The domain was registered on July 28, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar frequently associated with newly spun-up malicious infrastructure. It currently resolves to the IP address 64.7.198.11, which has been linked to prior phishing campaigns, though no specific autonomous system or geolocation details are available for further attribution. The domain is hosted behind Cloudflare nameservers (ligia.ns.cloudflare.com and porter.ns.cloudflare.com), a common tactic to obscure the true hosting provider and evade IP-based blocking.
VirusTotal telemetry shows that 12 of 91 security vendors flag app.meopex.com as malicious, a detection rate consistent with confirmed phishing domains. The domain appears on at least one security blocklist, and it is actively blocked by PhishDestroy, indicating recent validation of its fraudulent intent. No Safe Browsing or Open Threat Exchange (OTX) data is currently available, and the exact content of the site has not been analyzed; however, the domain name and infrastructure pattern suggest it is designed to harvest financial credentials, likely targeting users of a payment or fintech service. Defenders should treat this domain as a confirmed threat.
Immediate actions include blocking resolution at the DNS level, adding the domain to web-proxy and email-filtering denylists, and monitoring for connections to the associated IP 64.7.198.11. Given the domain's recent registration and use of Cloudflare, takedown efforts may be challenging, but reporting to the registrar (Trustname.com) and Cloudflare's abuse channels is recommended. Security teams should also review logs for any prior interactions with this domain or IP to identify potential compromised accounts or data exposure.