swanbitcoinpolicy[.]info
“DocuSign - Download to View Document”
Evidence Summary
This domain, swanbitcoinpolicy.info, is identified as a brand impersonation threat targeting Bitcoin users through a fraudulent DocuSign-themed interface. Analysis indicates the site presents a "Download to View Document" prompt, a common tactic to distribute malicious payloads or harvest login credentials. The domain specifically mimics cryptocurrency services, increasing the likelihood of targeting wallet holders or exchange users. Infrastructure analysis reveals the domain was registered via NICENIC INTERNATIONAL GROUP CO., LIMITED on May 27, 2024, and resolves to the IP address 104.21.8.58, hosted on Cloudflare’s AS13335 network. Detection metrics show 22 out of 95 security vendors on VirusTotal flagged the domain as malicious. It appears on one security blocklist and is currently blocked by PhishDestroy. The SSL certificate is issued by Let’s Encrypt, a detail often exploited by threat actors to lend superficial legitimacy to phishing sites. As of the latest assessment, swanbitcoinpolicy.info has been taken offline, reducing immediate exposure. However, the domain’s registration remains active, and similar infrastructure may be reused for future campaigns. Users who interacted with the site should assume potential credential compromise and monitor associated accounts for unauthorized activity. Organizations are advised to update blocklists with the provided indicators and educate users on recognizing cryptocurrency-themed phishing attempts.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260531-87C953- Captured page title
- DocuSign - Download to View Document
- PDF artifact
- PDF evidence
Full evidence text
Acceptable Use Policy (AUP): The domain swanbitcoinpolicy.info is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The use of this domain for fraudulent purposes constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such violations.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computer systems and the use of such access to commit fraud.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, which applies to phishing activities.
CAN-SPAM Act (15 U.S.C. § 7701): This act regulates commercial email and prohibits misleading headers and deceptive subject lines, which are often employed in phishing schemes.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. Non-compliance with your own policies and applicable laws could result in significant repercussions.
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | swanbitcoinpolicy.info/ |
malware | Detects file containing Telegram Bot API |
| DigiCert UltraDNS | swanbitcoinpolicy.info |
malicious | Sinkholed |
| Cloudflare DNS | swanbitcoinpolicy.info |
malicious | Sinkholed |
| OpenDNS | swanbitcoinpolicy.info |
phishing | Phishing Block |
| Quad9 DNS | swanbitcoinpolicy.info |
malicious | Sinkholed |
| DNS4EU | swanbitcoinpolicy.info |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
5 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of swanbitcoinpolicy.info · checked May 31, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive