The domain usddswap.org was registered on 29 July 2026 through the corporate entity Fewmoretaps OU d/b/a Trustname.com. Its authoritative name servers are ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz and ns2.anycastdns.cz, indicating use of a mixed hosting and anycast DNS configuration. DNS resolution points to the IPv4 address 186.2.175.35, which is currently reachable and hosts the active web service.
The site has been added to a single public security blocklist and is also listed by the PhishDestroy filtering service, confirming that at least one external sinkhole has taken action against it. VirusTotal records show that 91 antivirus and URL‑reputation vendors have examined the URL; none issued a detection, but the absence of a flag does not constitute a safety assurance. No SSL certificate details, HTTP response codes, page title, or content snapshots are available in the provided intelligence, leaving the exact lure and credential‑harvesting technique undocumented.
Likewise, no attribution to a specific brand or service is observable, so the threat is classified as a generic credential‑harvesting site. Defenders should proactively block the domain and its resolving IP address at perimeter and DNS layers, monitor outbound connections for attempts to resolve or contact 186.2.175.35, and incorporate the domain into internal threat‑intel feeds. Continuous re‑scanning with URL‑reputation services is advised to capture any future malicious payloads that may be introduced.