Analysis of the domain cake-swap.org indicates it is an active phishing site targeting cryptocurrency users, registered on July 24, 2026, through Fewmoretaps OU operating as Trustname.com. The domain currently resolves to the IP address 186.2.175.35, with nameservers configured under ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com. As of July 28, 2026, the domain appears on one security blocklist, though it has not been flagged by any of the 91 vendors that scanned it on VirusTotal. The absence of detections in this scan does not confirm the domain's safety, and its continued activity suggests it remains a potential threat.
Infrastructure analysis reveals the domain is hosted on an IP address that may be associated with other malicious activity, though specific hosting provider details are not yet confirmed. The registrar, Trustname.com, is known for facilitating domains used in phishing campaigns, though this alone does not confirm malicious intent. Defenders should note that the domain's recent registration and lack of widespread detection may indicate an early-stage campaign or evasion of automated detection systems.
Organizations are advised to monitor network traffic for connections to 186.2.175.35 and the domain cake-swap.org, particularly in environments where cryptocurrency transactions occur. Blocking the domain at the DNS or firewall level is recommended until further analysis confirms its legitimacy. Additional investigation into the site's content and any associated wallet addresses or transaction patterns is necessary to determine the full scope of the threat.