Analysis of the domain muesex.com indicates it is a recently established phishing infrastructure with high-risk characteristics. The domain was registered on July 25, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar commonly associated with low-reputation registrations. As of July 30, 2026, the domain remains active and resolves to the IP address 104.21.10.111, which is hosted on Cloudflare's network, a common tactic to obscure the true origin of malicious sites. Nameservers addilyn.ns.cloudflare.com and zod.ns.cloudflare.com further confirm Cloudflare's involvement in the domain's DNS resolution.
Detection data is limited but notable: one of 91 security vendors on VirusTotal has flagged the domain as malicious, and it appears on at least one security blocklist, specifically PhishDestroy. The exact nature of the phishing content is not yet analysed, as no brand target or page title has been identified in the available intelligence. Defenders should treat this domain as a potential threat vector for credential harvesting or malware distribution, given its recent registration and active status. Infrastructure analysis reveals no additional indicators of compromise beyond the current resolution and registrar details.
No SSL certificate data or HTTP response codes are provided, limiting further assessment of the domain's operational status. Given the domain's inclusion on a security blocklist and its Cloudflare-hosted infrastructure, defenders are advised to block traffic to and from 104.21.10.111 and monitor for any attempts to access muesex.com within their networks. Additional scrutiny of domains registered through the same registrar during this period may also be warranted to identify related threats.