sanctum-dex.com was registered on July 22, 2026 through Fewmoretaps OU d/b/a Trustname.com. The domain resolves to the IPv4 address 186.2.175.109 and is served by four authoritative name servers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com. VirusTotal has observed the domain in five of ninety‑one scanned security vendors, indicating that a subset of commercial scanners have flagged it as malicious. The domain is currently listed on one external blocklist and has been explicitly blocked by the PhishDestroy mitigation service, confirming that at least one dedicated anti‑phishing platform considers it a threat.
The infrastructure remains active as of the report date (July 30, 2026). No public evidence of SSL certificates, HTTP response codes, page titles, or associated malware kits has been disclosed, leaving the exact payload and victim‑targeting details unknown. The limited detection footprint—five vendor flags and a single blocklist entry—suggests that the campaign may be in an early deployment stage or using a low‑profile hosting arrangement. Defenders should proactively deny network traffic to 186.2.175.109, add sanctum-dex.com to DNS‑based blocklists, and monitor the listed name servers for any changes that could indicate additional command‑and‑control points.
Continuous re‑scanning on VirusTotal or similar platforms is advised to capture any future vendor detections. Organizations that employ email filtering should treat any messages containing links to this domain as malicious and quarantine them. Because the domain is newly created, threat actors may be leveraging the short registration window to avoid legacy reputation systems; therefore, rapid response and inclusion in internal blocklists is recommended.