The domain comp-swap.pro was registered on July 24, 2026, through Fewmoretaps OU d/b/a Trustname.com. As of July 28, 2026, it remains active and resolves to the IP address 186.2.175.35. Infrastructure analysis reveals the domain is hosted on nameservers ns1.anycastdns.cz and ns2.anycastdns.cz, a configuration often associated with bulletproof or low-reputation hosting providers. The domain appears on one security blocklist, specifically PhishDestroy, which flags it as part of a generic phishing operation.
No detections were recorded by the 91 vendors that scanned the domain on VirusTotal, though this absence does not confirm safety and may reflect delayed or incomplete coverage. The domain name, comp-swap.pro, suggests a potential impersonation of computer support or hardware exchange services, though no specific brand or page content has been confirmed in available data. The exact nature of the phishing scheme—whether targeting credentials, financial data, or technical support fraud—remains unconfirmed.
Defenders should treat this domain as suspicious based on its recent registration, blocklist presence, and hosting infrastructure. Network-level blocking at 186.2.175.35 and monitoring for related domains using the same nameservers or registrar are recommended. Further analysis of HTTP headers, SSL certificates, and page content is required to determine the precise threat vector and any associated phishing kit.