Analysis of sanctum-dex.net indicates that the domain is actively being used for phishing. The domain was registered on July 30, 2026 through Fewmoretaps OU d/b/a Trustname.com and is delegated to four nameservers: ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz. DNS resolution points to the single IPv4 address 186.2.175.35.
The domain has been indexed by at least one security blocklist and is explicitly blocked by the PhishDestroy feed, confirming that defensive communities have already identified it as malicious. A VirusTotal scan was performed by 91 antivirus engines; none of the scanners reported a detection, but the absence of detections does not constitute a safety guarantee and should be weighed against the other indicators of compromise. No additional public intelligence such as Safe Browsing alerts, OTX mentions, SSL certificate details, or HTTP response codes is currently available, leaving the exact content and payload of the site unverified.
Defenders should therefore treat the domain as a high‑confidence phishing indicator: block the domain and its resolving IP at perimeter firewalls, proxy filters, and endpoint DNS controls; add the domain to internal threat intel feeds; and monitor for any related C2 activity or credential harvesting attempts. Continuous re‑evaluation is advised as further evidence, such as page titles or payload analysis, may emerge.