Analysis indicates that mooniswap.net was registered on 24 July 2026 through the registrar Fewmoretaps OU operating under the trade name Trustname.com. The domain resolves to the IPv4 address 186.2.175.109 and is served by four name servers: ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz and ns2.anycastdns.cz. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy sinkhole, confirming that threat‑intelligence feeds have flagged it as malicious.
A VirusTotal scan performed by 91 anti‑malware engines returned no detections at the time of analysis; the absence of a detection does not imply benign intent, and the domain continues to be listed as active. No SSL certificate details, HTTP response codes, Safe Browsing verdicts, or page‑title information are currently available, limiting the ability to assess the content served by the site. The limited observable infrastructure—recent creation date, use of generic name‑servers, and association with a known phishing‑blocking service—matches patterns typical of rapidly deployed phishing infrastructure.
Defenders should continue to block the domain at perimeter filters, monitor DNS queries for the 186.2.175.109 address, and add the domain to internal deny lists. Additional investigation, such as fetching the HTTP response and analyzing page content, is required to confirm the phishing payload and to identify any credential‑harvesting forms that may be hosted.