Analysis indicates that poubex.com is currently active and has been identified as a generic phishing threat. The domain was registered on May 04, 2026 through Fewmoretaps OU d/b/a Trustname.com and is hosted on Cloudflare infrastructure, using the authoritative nameservers aspen.ns.cloudflare.com and roan.ns.cloudflare.com. DNS resolution points to the IPv4 address 64.7.198.11. The domain appears on one public security blocklist and is specifically listed by the PhishDestroy blocklist, confirming that at least one anti‑phishing service has taken it down.
VirusTotal scans show that two of ninety‑one security vendors have flagged the domain, providing independent confirmation of malicious intent. No additional public intelligence such as Safe Browsing verdicts, Open Threat Exchange reports, or page‑title analysis is available at this time, so the exact content and targeted brand remain unconfirmed. However, the combination of recent registration, Cloudflare hosting, blocklist inclusion, and vendor detections satisfies a high‑risk profile for phishing campaigns. Defenders should immediately block DNS resolution for poubex.com at the network perimeter, add the IP 64.7.198.11 to any existing sinkhole or deny‑list, and monitor outbound connections for attempts to contact the domain.
Continuous re‑scanning with VirusTotal and other multi‑engine services is advised to capture any escalation in detection counts. Logging of TLS handshake attempts can provide further visibility, as the domain likely presents a TLS certificate issued by Cloudflare. Organizations should also consider notifying users of the emerging threat, especially if credential‑collection vectors are suspected. Ongoing observation of the registrar Fewmoretaps OU activity may reveal additional domains that share the same abuse patterns.