# on-punch.fun — SUSPICIOUS > on-punch.fun poses as an Airdrop scam site, created March 28, 2026. With 0/95 VirusTotal detections, users risk fake crypto giveaways. ## Summary PhishDestroy identifies on-punch.fun as a domain actively impersonating Airdrop promotions to deceive users into submitting cryptocurrency or personal credentials. The page title 'パンチ | AirDrop' reveals the fraudulent intent to capitalize on the popularity of legitimate AirDrop campaigns while targeting unsuspecting victims. Fake airdrops often promise free tokens or exclusive rewards to trick users into connecting wallets or making deposits, leading to direct financial theft. This domain exemplifies a growing trend where threat actors exploit trending services to distribute malware or steal assets under the guise of promotional offers. This domain was flagged under active investigation with clear indicators of malicious intent. According to threat intelligence, on-punch.fun registered on March 28, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a known domain registrar with minimal identity verification. The domain resolves to IP 104.21.5.75 and utilizes a Let's Encrypt SSL certificate to appear legitimate, despite its recent creation. Currently, VirusTotal detects 0 out of 95 engines flagging the domain, indicating it remains under the radar of most security tools. This low detection rate highlights the importance of proactive monitoring and user vigilance, as malicious domains often fly under the radar until widespread attacks occur. Users who visited on-punch.fun should immediately cease any interaction and assess their exposure. If any cryptocurrency was sent or login credentials were entered, contact the respective wallet provider or platform support to secure accounts and monitor for unauthorized transactions. Avoid downloading any software or files from the site. Report the domain to your browser’s security team and consider using a reputable ad-blocker or DNS filtering service to block similar threats. Always verify the authenticity of airdrop campaigns by checking official project websites or social media channels for confirmed announcements. Staying informed and cautious is the best defense against evolving impersonation scams. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: Airdrop Scam - Page title: パンチ | AirDrop ## Domain Intelligence - Registered: 2026-03-28 18:43:50 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - IP: 104.21.5.75 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/99bd988f-d5e6-4cc9-a27a-1ed759290a8a - PhishDestroy: https://phishdestroy.io/domain/on-punch.fun/ - LLM endpoint: https://phishdestroy.io/domain/on-punch.fun/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/on-punch.fun/ Last updated: 2026-03-28