Analysis of coredex.pro shows that the domain was registered through Hostinger Operations, UAB on July 17 2026. The authoritative name servers are bonnie.ns.cloudflare.com and garrett.ns.cloudflare.com, indicating the use of Cloudflare’s DNS service. DNS resolution points to the IP address 172.67.162.100, which belongs to Cloudflare’s edge network, a common choice for malicious operators seeking to hide origin infrastructure.
The domain has been added to two public blocklists and is currently listed by PhishDestroy and ScamSniffer, confirming that at least two anti‑phishing feeds consider it malicious. VirusTotal reports that the domain was scanned by 91 antivirus or URL‑reputation vendors; none of the vendors flagged the domain at the time of scanning, but the absence of detections does not constitute evidence of benign intent. No public information is available regarding SSL certificate details, HTTP response codes, or the page title, and no evidence from Safe Browsing, OTX, or other reputation services has been disclosed.
Consequently, the operational purpose of the site remains uncertain beyond the classification as a generic phishing campaign. Defenders should block DNS resolution to 172.67.162.100 for any internal users, add coredex.pro to web‑proxy and endpoint deny lists, and monitor outbound traffic for attempts to contact the domain. Continuous re‑evaluation is advised, as the hosting provider may change the underlying IP or the threat actor could deploy additional payloads that would be detected by future scans.