Analysis of dflow-dex.com as of 30 July 2026 shows that the domain was registered on 22 July 2026 through the registrar Fewmoretaps OU operating as Trustname.com. The domain resolves to the IPv4 address 186.2.175.109 and is served by four nameservers – ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz and zeus.trustname.com – indicating the use of a mixed DNS infrastructure. Reputation services have placed the domain on a single security blocklist, and the PhishDestroy service explicitly blocks it, confirming its classification as a phishing resource.
VirusTotal scans have returned five positive detections out of ninety‑one submitted scanners, reinforcing the malicious rating despite a minority of engines lacking a verdict. The domain remains active, with no indication of takedown or remediation at the time of analysis. Defenders encountering traffic to dflow-dex.com should block the domain at perimeter firewalls, proxy servers, and DNS filtering solutions.
Network monitoring should flag any connections to 186.2.175.109, and endpoint protection should be configured to treat the five VirusTotal detections as indicative of malicious activity. Given the recent registration date, the limited blocklist exposure, and the mixed detection profile, the infrastructure is likely in an early deployment stage, and threat actors may be testing delivery vectors. Continuous re‑evaluation of the domain’s reputation, especially as additional scanners update their verdicts, is recommended to maintain an up‑to‑date defensive posture.