The domain mtron.vip was registered through GoDaddy.com, LLC on July 23, 2026 and is currently resolved to the IPv4 address 47.237.82.198. Its authoritative nameservers are ns29.domaincontrol.com and ns30.domaincontrol.com, both standard GoDaddy control points. Within a few days of creation the domain has been observed on three independent security blocklists and is actively blocked by the PhishDestroy, MetaMask, and SEAL filtering services, indicating that multiple threat‑intel feeds have correlated it with malicious activity.
VirusTotal analysis shows that two of ninety‑one scanned security vendors flagged the domain, providing additional confirmation of its hostile nature. The domain remains active as of the report date, July 28, 2026, and no evidence of takedown or remediation has been recorded. While the exact phishing payload or targeted brand has not been disclosed, the classification as generic phishing is supported by its rapid appearance on blocklists and the modest vendor detection count.
Defenders should add mtron.vip to deny‑list rules at the DNS and proxy layers, monitor traffic to the associated IP address for anomalous patterns, and consider updating endpoint and web‑gateway signatures to include the observed blocklist identifiers. Continuous re‑scanning of the domain via multi‑vendor services is advised to capture any escalation in detection rates, and any future resolution changes should be correlated with the known nameserver set to assess potential infrastructure shifts.