pumpthebutton[.]lol
“Pump the Button”
Evidence Summary
www.pumpthebutton.lol is a generic phishing domain identified as hosting an investment scam. There is no evidence that it impersonates a specific brand or uses a drainer kit. The domain has been taken offline, but it previously presented itself with the page title 'Pump the Button'. Users searching for information on whether www.pumpthebutton.lol is safe or a scam should be aware that it has been flagged for phishing activities and is not considered secure.
Technical analysis shows that www.pumpthebutton.lol was registered through Porkbun, LLC on September 23, 2025, and resolved to the IP address 5.161.255.2, located in the US and hosted by Hetzner Online GmbH. The SSL certificate was issued by Let's Encrypt / E8. VirusTotal reports that 2 of 95 security vendors detect this domain as malicious, and it appears on one security blocklist (PhishDestroy). The site utilized technologies such as Tailwind CSS, Amazon Web Services, Caddy, Unpkg, reCAPTCHA, Htmx, Amazon S3, and HTTP/3. The Gridinsoft trust score for this domain is 0/100. Nameservers used include curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, and salvador.
Anyone who interacted with www.pumpthebutton.lol should be alert for potential compromise of sensitive information. Since this site was associated with a generic phishing investment scam, users should monitor their financial accounts for unauthorized activity and consider changing passwords and enabling two-factor authentication on all relevant accounts. Victims are encouraged to report the incident to their local cybercrime authority and to the blocklist service (PhishDestroy) for further investigation.
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | www.pumpthebutton.lol |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive