Analysis of guacgg-swap.com as of 28 July 2026 indicates that the domain was registered only five days earlier, on 23 July 2026, through Fewmoretaps OU operating as Trustname.com. The authoritative name servers listed are ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz, suggesting a mixed hosting arrangement that includes both Trustname‑managed and anycast DNS services. DNS resolution points to the IPv4 address 186.2.175.109; no additional IP aliases or CDN front‑ends are observed. The domain appears on a single external blocklist and is actively listed by the PhishDestroy sink‑hole, indicating that at least one security community has identified it as malicious.
VirusTotal records show that 91 scanning engines have examined the domain, none of which raised a detection at the time of the scan; this lack of a detection should not be interpreted as evidence of safety, only as an absence of current signatures. No public SSL certificate details, HTTP response codes, or page title information are available in the current intelligence set, limiting the ability to confirm the presence of a TLS layer or to assess the content served by the site. Consequently, the precise phishing vector—such as credential harvesting, account takeover, or malicious download—is not yet confirmed, though the classification as a generic phishing site is consistent with the blocklist entries. Defenders should treat guacgg-swap.com as a high‑confidence indicator of malicious activity.
Immediate actions include adding the domain and its resolving IP address to network deny lists, configuring web proxies to block HTTP/HTTPS requests to the name, and updating intrusion‑detection signatures that reference the observed nameserver set. Continuous monitoring of DNS queries for the listed name servers and the IP 186.2.175.109 is recommended to detect any subsequent infrastructure changes.