This domain, sologenic.vip, is currently flagged as a generic phishing threat and is under active investigation as of July 31, 2026. The domain remains operational and resolves to the IP address 186.2.175.35. It is listed on one security blocklist and is blocked by the PhishDestroy service, indicating that at least one independent threat intelligence source has identified it as malicious. VirusTotal has scanned this domain with 91 vendors, and none of them currently flag it as malicious. However, this absence of detections should not be interpreted as proof that the domain is safe; it may simply mean that the domain is new, has not been widely reported, or that the vendors have not yet updated their datasets.
The domain uses nameservers ns1.anycastdns.cz and ns2.anycastdns.cz, which are part of the anycastdns.cz infrastructure. No specific brand, page title, or scam category has been identified in the available intelligence, so the exact content and purpose of the site remain unanalyzed. Defenders should treat this domain with caution and assume it is hostile until proven otherwise. Recommended actions include blocking the domain and its associated IP at the network level, monitoring for any attempts to access it from internal systems, and reviewing logs for any connections to 186.2.175.35.
Additionally, since the domain is still active, it is advisable to report it to additional threat intelligence platforms and to the registrar for potential takedown. The lack of vendor detections on VirusTotal does not reduce the risk, and the presence on a blocklist plus the PhishDestroy block is sufficient to warrant defensive action. Organizations should educate users about the potential for phishing attempts originating from this domain and ensure that email filters and web proxies are configured to block it. Further investigation into the hosting provider and the anycastdns.cz nameservers may reveal additional infrastructure linked to this threat actor.