The domain voltmix.vip was registered on July 28, 2026 and is currently listed as an active generic phishing campaign. Administrative records show registration through Fewmoretaps OU d/b/a Trustname.com, with authoritative name servers ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz. DNS resolution points to the IPv4 address 151.236.22.38. The domain has been added to the PhishDestroy blocklist and appears on a single additional security blocklist, indicating that at least one external mitigation service has identified it as malicious.
VirusTotal reports that the domain was examined by 91 scanning engines, none of which raised a detection at the time of analysis; this absence of detections is not interpreted as a statement of safety, only as a lack of current signatures. The public threat intelligence record classifies the risk level as "under investigation" and notes the status as active, implying ongoing operations. Concrete evidence is limited to registration metadata, name‑server configuration, IP address, and blocklist presence; no information on SSL certificates, HTTP response codes, page titles, or brand targeting has been disclosed.
Consequently, the precise nature of the phishing payload, target audience, or compromised credentials remains uncertain. Defenders should consider immediate containment actions: block resolution of voltmix.vip and its associated IP address at network perimeters, add the domain to internal blocklists, and monitor for any related traffic patterns. Continuous re‑evaluation is advised, given the active status and the potential for new indicators to emerge as the campaign evolves.