The domain hashflow-dex.pro was registered on July 30 2026 through Fewmoretaps OU d/b/a Trustname.com. It resolves to the IPv4 address 186.2.175.35 and uses the Anycast DNS name servers ns1.anycastdns.cz and ns2.anycastdns.cz. The domain appears on a single security blocklist and has been flagged by the PhishDestroy feed, indicating that at least one reputable anti‑phishing service has observed malicious activity associated with it. VirusTotal records show that the domain was scanned by 91 antivirus and URL‑reputation engines, none of which raised a detection at the time of analysis; this lack of detections does not imply legitimacy and should be weighed against the blocklist evidence.
No public SSL certificate information, HTTP response codes, page title, or content snapshots are currently available, limiting the ability to assess the exact phishing vector or the targeted brand. Consequently, the precise payload, credential‑harvesting mechanisms, and victim profile remain uncertain. Defenders should treat hashflow-dex.pro as a high‑confidence phishing indicator.
Immediate actions include adding the domain and its resolved IP address to network‑level block lists, configuring web‑proxy and DNS filtering solutions to deny requests, and monitoring outbound traffic for connections to the listed nameservers. If the domain is observed in traffic, a deeper sandbox analysis of the landing page should be performed to capture any malicious scripts or redirects. Continuous re‑scanning with VirusTotal or similar services is advised to capture any future detections.