Analysis of the domain fnmux.com indicates it is under investigation for generic phishing activity as of July 31, 2026. The domain was registered on June 18, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently observed in phishing campaigns. It resolves to the IP address 158.94.211.169, which has not yet been widely flagged in public threat intelligence feeds but may warrant further scrutiny due to its association with recently registered suspicious domains. The domain utilizes nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, a configuration commonly seen in domains linked to malicious infrastructure.
VirusTotal scans conducted by 91 security vendors returned no detections at the time of this report; however, the absence of detections does not confirm the domain's safety, particularly given its recent registration and presence on at least one security blocklist. Specifically, the domain is currently blocked by PhishDestroy, a blocklist specializing in phishing threats. No additional details regarding the specific brand or service being impersonated, the phishing kit in use, or the exact content of the site are available at this time, as the domain's page title and other on-page indicators have not been analyzed.
Defenders are advised to treat this domain as potentially malicious based on its registration characteristics, nameserver configuration, and inclusion on a phishing-focused blocklist. Network-level blocking or monitoring of traffic to 158.94.211.169 and fnmux.com is recommended until further analysis can determine the scope and nature of the threat. Given the domain's recent creation and active status, continued vigilance and correlation with other threat intelligence sources are warranted to assess its evolving risk profile.