Analysis indicates that the domain toahax.com is actively engaged in credential-harvesting phishing operations as of July 28, 2026. Registered on July 23, 2026, through Fewmoretaps OU d/b/a Trustname.com, the domain resolves to the IP address 64.7.198.11. Infrastructure analysis reveals the use of Cloudflare nameservers (imani.ns.cloudflare.com and milan.ns.cloudflare.com), a common tactic to obscure hosting origins and evade immediate takedowns. Detection data from security vendors shows that five out of ninety-one engines on VirusTotal have flagged this domain as malicious, while it also appears on at least one security blocklist.
The domain is currently blocked by PhishDestroy, further corroborating its classification as a high-risk phishing resource. The exact content or targeted brand of the phishing site remains unconfirmed, as no specific page title, brand target, or scam type has been provided in available intelligence. However, the combination of recent registration, Cloudflare-based DNS, and partial vendor detections aligns with patterns observed in credential-theft campaigns.
Defenders are advised to treat this domain as hostile and implement blocking measures at the network and endpoint levels. Organizations should monitor for connections to 64.7.198.11 and review logs for any interactions with toahax.com, particularly in contexts involving login attempts or sensitive data submission. Given the domain's active status and high-risk classification, further investigation into its hosting infrastructure and potential affiliate links is recommended.