MALICIOUS — CRITICAL
sol-inicnerator[.]com
17 of 91 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer); the latest stored check returned HTTP 502.
- VirusTotal
- 17/91
- Blocklists
- 1 · ScamSniffer
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
sol-inicnerator.com — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Discord; Betrugstyp: Social Media Phishing. Zusammenfassung der Beweislage: VirusTotal 17/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Digest
sol-inicnerator.com is classified critical with an evidence score of 95/100. 17 of 91 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer). Registered 21 Feb 2026, hosted on 172.67.216.185 (CLOUDFLARENET, US, US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture.
Stored generated summary (templated)cerebras · 24.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
sol-inicnerator.com was registered on 21 February 2026 and currently resolves to the Cloudflare address 172.67.216.185, which is associated with AS13335 in the United States. The site presents the page title “Sol Incinerator” and carries an SSL certificate identified as “WE1”. Analysis by VirusTotal records nine of ninety‑three scanning engines flagging the domain, indicating malicious behavior.
The domain is listed on two dedicated phishing blocklists, PhishDestroy and ScamSniffer, both of which classify it as a social‑media phishing campaign that impersonates the Discord brand. The infrastructure appears to rely on Cloudflare’s reverse‑proxy service, obscuring the upstream host. As of the reporting date, the domain is taken offline, but historical activity suggests that it was used to harvest Discord credentials or redirect victims to credential‑stealing pages.
Defenders should continue to block the domain at DNS and web‑filter layers, monitor outbound connections to the associated IP, and incorporate the observed blocklist entries into threat‑intelligence feeds. Ongoing observation of the IP address and any future re‑registration of the domain is recommended, as the current evidence does not reveal the ultimate payload or post‑exploitation tactics employed.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.