iscan[.]solfam[.]cc
“iScans — Multi-Chain Portfolio Tracker”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
content_divergence- درجة الإخفاء
- 2/6
ملخص الأدلة
PhishDestroy identifies iscan.solfam.cc as an active generic phishing domain masquerading as a legitimate document-scanning portal. The infrastructure is currently unflagged by automated scanners, retaining a 17/95 detection score on VirusTotal as of seed a2d657. The domain was registered on April 15, 2026, resolving to IP 188.114.97.3 via a Let’s Encrypt SSL certificate and is hosted under NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar with historically low abuse oversight. No listings on public blocklists or trust-index downgrades have yet surfaced, indicating a first-stage campaign still in the evasion phase. This domain represents a generic phishing threat targeting users expecting document-processing services. Technical indicators include the April 15, 2026 creation date, IP 188.114.97.3 as the A record, and a recently issued Let’s Encrypt certificate serial common to fast-flux hosting. The registrar’s low reputation and zero VirusTotal detections highlight an elevated risk of successful user compromise before wider blacklisting occurs. The absence of current blocklist entries suggests a narrow targeting window where threat actors leverage fresh domains to harvest credentials or deliver malware under the guise of document workflows. Mitigation requires immediate DNS-level blocking of iscan.solfam.cc and the associated IP 188.114.97.3 across enterprise and endpoint layers. Users should treat any unexpected document-scanning prompts linking to this domain as malicious, avoiding data entry and reporting the lure to security teams. Network defenders should inspect SSL certificate telemetry for additional domains bearing the same Let’s Encrypt issuer fingerprint and proactively hunt for inbound TLS connections to 188.114.97.3 on port 443. Rapid takedown requests should be filed with NICENIC and Let’s Encrypt citing the domain’s fraudulent impersonation of document services and zero detections indicative of a live campaign.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260422-7F071B- عنوان الصفحة الملتقطة
- iScans — Multi-Chain Portfolio Tracker
- ملف PDF
- دليل PDF
النص الكامل للدليل
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
التقنيات
حُدّدت ٦ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of iscan.solfam.cc · checked Apr 22, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب