The domain alphaq-dex.com was registered on 22 July 2026 through Fewmoretaps OU operating under the name Trustname.com. It resolves to the IPv4 address 186.2.175.109 and is served by four nameservers: ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz. The domain is currently listed as active and appears on a single security blocklist. PhishDestroy has already blocked the domain, indicating prior detection by an anti‑phishing service.
VirusTotal reports that five of ninety‑one scanned vendors flagged the domain, suggesting that multiple security engines have identified malicious characteristics. No additional public threat intelligence feeds (such as OTX or Google Safe Browsing) are referenced in the available data, and no SSL certificate details or HTTP response codes have been disclosed. The limited evidence points to a newly created phishing infrastructure that is already being leveraged for malicious campaigns. Uncertainty remains regarding the specific payload or credential‑harvesting technique employed, as page content, brand targeting, and kit details have not been published.
Defenders should immediately add alphaq-dex.com and its resolve IP 186.2.175.109 to blocklists across email gateways, web proxies, and endpoint protection platforms. Continuous monitoring of the associated nameservers and any newly observed subdomains is advised, as the threat actor may expand the infrastructure rapidly. Analysts should also watch for any future VirusTotal submissions that could increase the detection count, and consider sharing any newly observed indicators of compromise with industry‑wide blocklists to improve collective protection.