# PhishDestroy threat dossier — panswap.pro ================================================================ Fetched: 2026-07-26 16:05:30 UTC Canonical: https://phishdestroy.io/domain/panswap.pro/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Wallet/Seed Phishing Targeted brand: across (and: aptos, arbitrum, base, binance, bnb chain) Phishing kit: Wallet Connect Abuse Wallet drainer: Wallet Connect Abuse ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/95 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, Lionic, Seclookup, SOCRadar, Sophos, VIPRE AlienVault OTX: 17 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist Victim re-reports (public form): 1 ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 158.94.209.215 (NL, Amsterdam) ASN: ASAS209800 metaspinner-asn metaspinner net GmbH, DE Hosting org: AS202412 Omegatech LTD Registrar: DevExpanse Ltd d/b/a Regery.com Nameservers: pns1.regery.net, pns2.regery.net, pns3.regery.net Registered: 2025-10-13 Expires: 2026-10-13 Page title: Pancake Swap ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: none Status: INVALID chain ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-10-13 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-25 02:39:27 UTC (by PhishDestroy tracker) First reported: 2025-10-18 16:15:30 UTC (abuse notice filed) Last verified: 2026-07-26 16:21:51 UTC Neutralised: 2026-05-08 05:36:29 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/0199f81a-6a1e-743c-ae60-8e69da5fa995/ Wayback Machine: https://web.archive.org/web/*/panswap.pro crt.sh CT logs: https://crt.sh/?q=%25.panswap.pro Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=panswap.pro AlienVault OTX: https://otx.alienvault.com/indicator/domain/panswap.pro URLhaus: https://urlhaus.abuse.ch/host/panswap.pro/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-23 09:50:33 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] panswap.pro Fake Across Crypto Drainer Alert Analysis of panswap.pro indicates a high-risk crypto drainer domain targeting users of the Across protocol. The domain, registered on October 13, 2025, through DevExpanse Ltd d/b/a Regery.com, impersonates Across and presents a page titled 'Pancake Swap,' though the exact content and visual mimicry remain unconfirmed. Infrastructure analysis reveals the domain resolves to 158.94.209.215 (AS202412 Omegatech LTD, Netherlands) and uses nameservers pns1.regery.net, pns2.regery.net, and pns3.regery.net. No SSL certificate is present, increasing the risk of unencrypted credential interception. The domain is associated with the 'Wallet Connect Abuse' phishing kit, a known vector for crypto drainer attacks. It appears on one security blocklist (PhishDestroy) and is flagged by 13 of 95 security vendors in VirusTotal scans. Gridinsoft assigns a trust score of 0/100, and AlienVault OTX records it in 17 threat intelligence pulses, suggesting active tracking by defenders. The domain is currently offline, but prior activity aligns with wallet/seed phishing tactics. Defenders should treat this domain as malicious and block it at DNS, proxy, and endpoint levels. Monitor for related infrastructure under the Regery.com registrar and Omegatech LTD hosting provider. Given the use of a known drainer kit, assume any prior interaction with this domain may have resulted in unauthorized wallet access or fund theft. No further content analysis is available, so defenders should rely on the provided indicators for detection and response. [Updates since narrative was generated:] - VirusTotal detections: now 13/95 (narrative was written when count was lower) ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/panswap.pro/ JSON API: https://api.destroy.tools/v1/check?domain=panswap.pro Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 198,549 domains (67,868 alive under monitoring, 129,132 confirmed takedowns/dead). Site: https://phishdestroy.io