The domain metadao-dex.com was registered on July 22 2026 through Fewmoretaps OU d/b/a Trustname.com. It resolves to the IPv4 address 186.2.175.109 and is served by four authoritative name servers – ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz. VirusTotal records show that five of ninety‑one scanned security vendors flagged the domain, indicating a non‑trivial detection rate among automated scanners. The domain is listed on a single public blocklist and is actively blocked by the PhishDestroy service, reinforcing the view that it is being used for malicious purposes.
No additional public intelligence such as Safe Browsing verdicts, Open Threat Exchange reports, SSL certificate details, HTTP response codes, or page‑title information is currently available, so the exact content and targeted brand remain unverified. Analysis of the infrastructure suggests a short‑lived registration coupled with the use of Anycast DNS providers, a pattern frequently observed in phishing campaigns that aim to evade takedown efforts. The presence of multiple trust‑named name servers may indicate an attempt to lend legitimacy to the domain, while the IP address 186.2.175.109 is not associated with a well‑known hosting provider in public records, limiting immediate attribution. The five vendor detections and the blocklist entry provide enough confidence to classify the domain as high‑risk for phishing activity, even though the specific victim lure has not been captured.
Defenders should add metadao-dex.com to local deny lists, enforce URL filtering, and monitor outbound traffic for connections to 186.2.175.109. Security solutions that integrate VirusTotal or PhishDestroy feeds will already flag the domain, but manual rule sets can reduce latency. Continuous re‑assessment is advised; additional evidence such as page titles, SSL fingerprints, or observed phishing email samples would refine the threat profile and support takedown requests.