just-swap[.]net
“JustSwap â TRON DEX · Swap TRC-20 Tokens · Low Fees · Stake & Earn”
Stored observation
Observed title contrast
Evidence Summary
just-swap.net is currently listed as an active generic phishing domain under investigation. The domain has been submitted to VirusTotal where it was scanned by 91 antivirus and URL‑reputation vendors; none of the engines generated a detection at the time of analysis. This lack of detections does not constitute a safety indication, as the scanners may not have observed malicious payloads or the URL may not have been actively probed. Independent threat‑intel feeds have flagged the domain: PhishDestroy has added it to its blocklist and it appears on one additional security blocklist, confirming that at least two reputable sources consider the host malicious.
No further technical details such as registrar information, IP address, ASN, TLS certificate, HTTP response code, or page title have been disclosed in the available intelligence. Consequently, the exact infrastructure used to host the site and any potential command‑and‑control or credential‑harvesting mechanisms remain unknown. Defenders should treat any traffic to or from just-swap.net as suspicious. Network‑level controls—such as firewall or DNS filtering—should be configured to block the domain, and endpoint protection solutions should be updated to include the domain in block lists.
Security teams should continue monitoring for new detections, especially any future VirusTotal scans that might produce positive matches, and should investigate logs for recent connections to the domain. Because the domain is already flagged by PhishDestroy, existing block‑list subscriptions that incorporate that feed will automatically mitigate exposure, but manual remediation is recommended for environments that do not ingest that feed. Analysts should also consider reviewing credential‑reuse policies and alerting users about the possibility of credential harvesting attempts linked to the domain. Ongoing verification of the domain’s status is advised until a formal determination of risk is completed.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
4 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive