Analysis of dooar-dex.com indicates a recently registered domain exhibiting characteristics consistent with phishing credential harvesting. The domain was created on July 22, 2026, and currently resolves to the IP address 186.2.175.109. Infrastructure analysis reveals the domain is hosted on nameservers ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com, with registration facilitated through Fewmoretaps OU d/b/a Trustname.com.
As of July 30, 2026, the domain appears on one security blocklist, and PhishDestroy has flagged it as malicious, though the domain remains active. VirusTotal scans conducted by 91 vendors returned no detections; however, the absence of detections does not confirm the domain's safety, particularly given its recent registration and limited exposure to security vendors. The domain's content has not been fully analyzed, and no specific brand impersonation or phishing kit has been confirmed in available intelligence.
Defenders are advised to treat this domain as suspicious based on its registration timeline, hosting infrastructure, and detection by a single security vendor. Network-level blocking at the IP and domain level is recommended pending further investigation. Continuous monitoring for changes in detection status or additional blocklist appearances is advised, as phishing domains often evolve rapidly in the days following registration.