Analysis of the domain trongas.fun indicates that it was registered on June 22, 2026 through Fewmoretaps OU d/b/a Trustname.com. The domain is delegated to four nameservers—ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz—suggesting use of a mixed hosting and DNS service. Network resolution points to the IPv4 address 186.2.175.35, which remains active as of the report date, July 30, 2026.
The domain has been listed on a single security blocklist and is explicitly blocked by the PhishDestroy service, confirming that at least one defensive feed has identified it as malicious. VirusTotal reports that the domain was scanned by 91 antivirus engines, none of which raised a detection; this absence of detections does not constitute evidence of safety and should be interpreted as a lack of current signatures rather than a clean bill of health. No public information is available regarding SSL/TLS configuration, HTTP response codes, page title, or any observed brand impersonation, leaving the exact phishing payload or target unknown.
Given the recent creation date, active resolution, and inclusion on a blocklist, defenders should treat trongas.fun as a high‑confidence phishing indicator. Recommended mitigation steps include adding the domain and its resolving IP address to network deny lists, monitoring DNS queries for the listed nameservers, and employing URL filtering to block access. Continuous re‑evaluation is advised, as additional intelligence—such as page content, observed credential harvesting, or expanded blocklist presence—may emerge and refine the threat profile.