Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
punkswap[.]net
“PunkSwap v6.3 | Offers UI + All Features”
Resumo das evidências
The domain punkswap.net is a generic phishing site targeting cryptocurrency users. It presents itself as a legitimate platform but operates as a scam to deceive victims into disclosing sensitive information or transferring digital assets. No specific brand is impersonated, and no drainer kit was identified. As of the latest verification, punkswap.net has been taken offline.
Technical indicators confirm the elevated risk. punkswap.net was flagged by 1 of 95 VirusTotal security vendors, including SOCRadar, and appears on 1 security blocklist (PhishDestroy). The domain was registered through Name.com, Inc. on February 21, 2026, and resolves to the IP address 64.29.17.1, hosted on Amazon.com, Inc.'s infrastructure (AS16509) in the US. The SSL certificate was issued by Let's Encrypt (R12), and the observed page title was 'PunkSwap v6.3 | Offers UI + All Features'. Technologies detected include Vercel and HSTS, with nameservers ns1.vercel-dns.com and ns2.vercel-dns.com. Google Safe Browsing does not currently flag the domain.
Users who interacted with punkswap.net should immediately revoke any token approvals granted to the site and transfer remaining funds to a new, secure wallet. Monitor transaction history for unauthorized activity and report the domain to relevant platforms, such as the registrar (Name.com, Inc.), PhishTank, or local cybercrime authorities. If credentials were entered, change passwords for all associated accounts and enable two-factor authentication where available.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260220-8A5C5E- Título da página capturada
- PunkSwap v6.3 | Offers UI + All Features
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Acceptable Use Policy (AUP): The domain punkswap.net is actively engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain violates your TOS, which reserves the right to suspend or terminate services for any activities that are illegal or harmful, including phishing.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is relevant as phishing schemes often involve unauthorized access to personal information.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities through electronic communications, applicable to the fraudulent activities associated with punkswap.net.
Anti-Phishing Act: Various jurisdictions have specific laws targeting phishing, which criminalize the act of using deceptive means to obtain sensitive information.
Regulatory Note: Failure to take immediate action against punkswap.net may expose your organization to legal liability and regulatory scrutiny. Non-compliance with your own policies and applicable laws could result in significant penalties.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | static.network.keeta.com/keetanet-browser.js |
audit | Hunting_JS_WebAssembly |
| DigiCert UltraDNS | ipfs.io |
malicious | Sinkholed |
| Cloudflare DNS | w3s.link |
malicious | Sinkholed |
| DNS4EU | bafybeie7qko5mlbdaix6kbdxcgukls7dezwn4ql3pq6bktcgcviwztceey.ipfs.dweb.link |
malicious | Sinkholed |
| Cloudflare DNS | bafybeie7qko5mlbdaix6kbdxcgukls7dezwn4ql3pq6bktcgcviwztceey.ipfs.w3s.link |
malicious | Sinkholed |
| Hagezi Threat Feed | bafybeie7qko5mlbdaix6kbdxcgukls7dezwn4ql3pq6bktcgcviwztceey.ipfs.4everland.io |
malicious | Sinkholed |
| Quad9 DNS | bafybeie7qko5mlbdaix6kbdxcgukls7dezwn4ql3pq6bktcgcviwztceey.ipfs.4everland.io |
malicious | Sinkholed |
| DNS4EU | bafybeie7qko5mlbdaix6kbdxcgukls7dezwn4ql3pq6bktcgcviwztceey.ipfs.4everland.io |
malicious | Sinkholed |
| Hagezi Threat Feed | 4everland.io |
malicious | Sinkholed |
| Quad9 DNS | 4everland.io |
malicious | Sinkholed |
| DNS4EU | dweb.link |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo