Analysis of the domain asterdex-dex.com indicates a confirmed high-risk phishing operation targeting cryptocurrency users, active as of July 30, 2026. The domain was registered on July 22, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar frequently associated with newly established phishing infrastructure. Infrastructure analysis reveals the domain resolves to the IP address 186.2.175.109, with nameservers configured as ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com, suggesting the use of bulletproof or low-reputation DNS providers commonly exploited for malicious campaigns. Security vendor detections on VirusTotal show 5 of 91 engines flagging the domain as malicious, providing concrete evidence of its phishing classification.
The domain is currently blocked by PhishDestroy and appears on at least one security blocklist, further corroborating its fraudulent nature. While the exact content of the site has not been fully analyzed, the domain name, combined with the detection context, strongly suggests an intent to deceive users into interacting with a fraudulent cryptocurrency exchange or decentralized finance (DeFi) platform. Defenders are advised to treat this domain as an active threat.
Network-level blocking of the IP 186.2.175.109 and associated nameservers is recommended to mitigate exposure. Organizations should monitor for connections to this domain within their logs and consider proactive takedown requests through Trustname.com or relevant hosting providers. Given the domain's recent registration and active status, heightened vigilance is warranted, particularly for users or systems interacting with cryptocurrency-related services.