Analysis of cropper-dex.com indicates that the domain was registered on July 22 2026 through Fewmoretaps OU d/b/a Trustname.com. The domain resolves to the IPv4 address 186.2.175.109 and is currently active. DNS configuration lists four authoritative nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com, all of which are commonly associated with bulk DNS services. VirusTotal reports that six of ninety‑one scanning engines have raised alerts on the domain, suggesting that some security products have identified malicious characteristics.
The domain is listed on a single public blocklist and is explicitly blocked by the PhishDestroy feed, confirming that at least one anti‑phishing community has taken mitigation action. No additional public reputation services, Safe Browsing checks, or SSL certificate details were provided in the source data. Consequently, the observable evidence points to an infrastructure that is deliberately short‑lived, leveraging a recently created domain, shared DNS infrastructure, and a public IP address that may be part of a larger hosting pool. The limited detection coverage (six detections) and the presence on only one blocklist indicate that the campaign may still be in early deployment or that detection signatures have not yet been widely propagated.
Defenders should add the domain and its resolving IP address to outbound and inbound block rules, monitor DNS queries for the listed nameservers, and consider sharing the indicator with threat‑intel sharing platforms. Continuous re‑query of the domain against dynamic reputation services is recommended to capture any future classification changes. Until further content analysis is available, the domain should be treated as a high‑risk phishing vector.