The domain jpool-dex.net was registered on July 23, 2026 and is presently active. It resolves to the IPv4 address 186.2.175.109, which geolocates to Belize and is hosted by Iqweb LLC. Registration details show the domain was filed through Fewmoretaps OU doing business as Trustname.com, and the authoritative name servers are ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz. An SSL certificate issued by Let’s Encrypt (labelled YR1) is currently valid, indicating the site can serve HTTPS traffic without certificate errors.
The domain appears on a single security blocklist and has been specifically blocked by the PhishDestroy service, reinforcing its classification as a malicious resource. VirusTotal records indicate the domain was scanned by 91 anti‑malware vendors, none of which reported a detection; this absence does not constitute a safety assurance and may reflect the recency of the domain’s deployment. No information is available regarding the page title, targeted brand, or the specific phishing kit employed, leaving the exact lure and victim profile unknown.
Defensive operators should add jpool-dex.net to DNS‑based blocklists, enforce safe‑browsing checks, and monitor any TLS handshake anomalies associated with its Let’s Encrypt certificate. Continuous observation of the domain’s DNS records and hosting infrastructure is recommended to detect potential changes, such as new IP assignments or additional name‑server configurations, which may indicate an expansion of the phishing campaign. Given the recent creation date and limited detection history, proactive containment is advisable to prevent possible credential harvesting or credential‑reuse attacks.