This domain, swap-byreal.com, was registered on July 22, 2026, through Fewmoretaps OU d/b/a Trustname.com and remains actively resolving to the IP address 186.2.175.109. Analysis indicates a high-risk phishing infrastructure, with 7 of 91 security vendors on VirusTotal flagging the domain as malicious. The domain appears on at least one security blocklist, reinforcing its classification as a potential threat.
Nameserver infrastructure includes ares.trustname.com, zeus.trustname.com, and anycast DNS servers ns1.anycastdns.cz and ns2.anycastdns.cz, which may suggest shared or bulletproof hosting practices commonly associated with phishing operations. The domain's recent creation and rapid detection by security vendors align with typical phishing campaign timelines, where domains are registered shortly before deployment to evade reputation-based defenses. While the exact content of the site has not been analyzed, the available indicators—including detection by PhishDestroy and its presence on a security blocklist—point to a likely credential-harvesting or financial scam operation.
Defenders should treat this domain as malicious and prioritize blocking it at the DNS, proxy, or firewall level. Additional investigation into the hosting IP (186.2.175.109) and associated domains may reveal further compromised infrastructure. Given the domain's active status and detection by multiple security vendors, organizations should monitor for connections to this domain in logs and network traffic, particularly from endpoints handling sensitive financial or authentication data.