Analysis indicates defiswap-dex.com is an active crypto-drainer phishing domain registered on July 24, 2026, through Fewmoretaps OU operating as Trustname.com. The domain currently resolves to IP address 186.2.175.109 and uses nameservers ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com. As of July 28, 2026, the domain appears on one security blocklist, specifically PhishDestroy, confirming detection by at least one commercial threat feed. No additional brand target or scam kit details are currently available, and the exact content of the site remains unanalysed.
VirusTotal scans conducted by 91 vendors returned no detections; however, the absence of flags does not confirm safety and may reflect a lack of prior exposure or evasion techniques. The domain remains operational, and infrastructure analysis reveals no indications of takedown or suspension. Registrar and hosting patterns align with known phishing infrastructure, though no direct attribution to a specific threat actor or campaign is established. Defenders are advised to treat defiswap-dex.com as a confirmed phishing domain targeting cryptocurrency users.
Blocking the domain, associated IP, and nameservers at the network level is recommended. Security teams should monitor for connections to 186.2.175.109 and correlate with internal logs for potential compromise. Further investigation into the site’s functionality and payload delivery is ongoing, and updates will be provided as new evidence emerges.