Analysis of the domain moscowusdt.pro indicates it is an active phishing site under investigation as of July 31, 2026. The domain was registered on July 30, 2026, through Fewmoretaps OU operating under the name Trustname.com. Infrastructure analysis reveals the domain resolves to the IP address 186.2.175.35, with nameservers configured as ns1.anycastdns.cz and ns2.anycastdns.cz. At present, the domain appears on one security blocklist and has been flagged by PhishDestroy, though it remains unconfirmed by other major detection vendors.
VirusTotal scans conducted by 91 security vendors returned no detections as of the latest assessment. However, the absence of detections does not constitute proof of safety, particularly given the domain's recent registration and association with a known phishing infrastructure pattern. The registrar, Trustname.com, has been previously linked to domains involved in fraudulent activities, though no direct evidence ties this specific registration to prior campaigns. The domain's name, moscowusdt.pro, suggests a potential focus on USDT (Tether) cryptocurrency phishing, though the exact content and mechanisms of the site remain unanalyzed.
Defenders are advised to monitor network traffic for connections to 186.2.175.35 and the domain itself, particularly in environments where cryptocurrency transactions occur. Given the domain's recent creation and limited detection coverage, organizations should treat it as high-risk until further analysis or additional vendor detections provide clarity. No SSL certificate details or HTTP response data were available for review, and the specific phishing kit or brand impersonation—if any—has not been identified. Continued vigilance and proactive blocking are recommended for security teams.