Analysis of defituna-dex.com indicates that the domain was registered on July 22, 2026 through Fewmoretaps OU d/b/a Trustname.com and is actively resolving to the IPv4 address 186.2.175.109. The domain appears on a single security blocklist and has been specifically flagged by the PhishDestroy blocklist, suggesting that at least one external threat‑intelligence source has identified malicious activity associated with the host. VirusTotal records show that the domain has been examined by 91 scanning vendors; at the time of the latest scan none of the vendors reported a detection, but the absence of a detection does not constitute confirmation of safety.
The authoritative name servers for the zone include ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com, indicating the use of a mixed hosting configuration that may aid in resilience or evasion. The only publicly disclosed threat category is “crypto drainer,” implying that the site is intended to illicitly redirect or siphon cryptocurrency assets from victims. No additional data such as SSL certificates, HTTP response codes, or page titles have been disclosed, leaving the exact delivery mechanism and victim interaction surface unclear.
Defenders should treat the domain as hostile, block network resolution to 186.2.175.109, add the domain to proxy and DNS filtering policies, and monitor for any outbound connections to the listed nameservers. Continuous re‑evaluation is advised, as future scans or threat‑intel updates may reveal further indicators of compromise.