Analysis of the domain heroswap-dex.com shows that it is actively used for phishing operations as of the report date, July 28, 2026. The domain was registered on July 23, 2026 through Fewmoretaps OU d/b/a Trustname.com and resolves to the IPv4 address 186.2.175.109. Infrastructure observations indicate that the domain is served by four nameservers—ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz—suggesting the use of a shared DNS service typical of disposable malicious sites.
The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy feed, reinforcing its classification as a phishing vector. VirusTotal reports that the domain was scanned by 91 security vendors, and none have currently flagged it, but this absence of detection does not constitute a safety guarantee. No public intelligence regarding SSL certificates, HTTP response codes, page titles, or brand impersonation has been released, leaving those surface characteristics unverified.
Given the confirmed phishing status, defenders should add heroswap-dex.com to network perimeter blocklists, enforce DNS sinkholing for the associated IP address 186.2.175.109, and monitor the four listed authoritative name servers for any changes that could indicate new malicious payloads. Continuous re‑inspection of VirusTotal and other sandbox services is recommended to capture any future detections, and security teams should remain alert for emerging indicators that may link the domain to broader credential‑stealing campaigns.