punch-migrate[.]live
Перевірка домену punch-migrate.live на фішинг і безпеку
“Punch on Sol | $PUNCH - The Coziest Monkey on Solana 🐵”
punch-migrate.live — Прикритий · доступний (HTTP 200). Уособлення бренду: Solana; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 90/100. Реєстратор: OwnRegistrar.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain punch-migrate.live was observed on 2026-07-12 exhibiting high-risk brand-impersonation activity targeting the Solana ecosystem. The site presents a page titled “Punch on Sol | $PUNCH - The Coziest Monkey on Solana 🐵”, a clear attempt to masquerade as an official Solana project and lure users into credential or token theft. Technical profiling shows the domain resolves to IP 104.21.82.138, hosted behind Cloudflare, Inc. in Canada. The authoritative nameservers are jill.ns.cloudflare.com and noel.ns.cloudflare.com, and the site serves a valid Let’s Encrypt certificate (E7). HTTP requests return status 200, indicating the front-end is actively delivering content. Open-source intelligence flags the domain as blocked by multiple defensive feeds, including PhishDestroy, MetaMask, and SEAL. AlienVault OTX lists the domain in a single threat pulse, and it appears on three external blocklists. The Gridinsoft trust score of 0/100 reflects an extremely malicious rating, while VirusTotal currently reports 0 detections out of 95 engines, suggesting the payload has not yet been identified by scanners. Analysts should treat punch-migrate.live as an active malicious infrastructure. Immediate mitigation steps include adding the domain and its resolving IP to network deny lists, monitoring DNS queries for the associated Cloudflare nameservers, and deploying URL filtering rules that capture the exact page title pattern. Continuous re-evaluation is advised, as the site may evolve to host additional phishing pages or malicious binaries.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога