koltracking[.]com
“KOL Tracking — Auto-Trade Solana on KOL Signals | 493 Wallets Tracked”
koltracking.com was registered on April 10, 2026 through Cloudflare, Inc. and currently resolves to the Cloudflare edge address 104.21.17.212, located in the United States under AS13335. The domain serves a page titled “KOL Tracking — Auto‑Trade Solana on KOL Signals | 493 Wallets Tracked”, which explicitly references the Solana brand and suggests automated trading services. The site returns HTTP 200 and presents a valid Let’s Encrypt certificate (YE1), indicating that the operators have taken basic steps to appear trustworthy. The authoritative nameservers aaron.ns.cloudflare.com and alla.ns.cloudflare.com are standard Cloudflare DNS endpoints, offering no direct insight into the underlying hosting environment. The use of Cloudflare’s reverse‑proxy and CDN services masks the true origin server, a common technique for phishing operators seeking to hide attribution. The low Gridinsoft trust score of 0/100 and the fact that the domain appears on a security blocklist further corroborate malicious intent. Open‑source intelligence flags koltracking.com in two AlienVault OTX pulses, and three of ninety‑five VirusTotal scanners have raised detections, demonstrating that independent analysis tools have begun to catalog the site as suspicious. PhishDestroy already blocks the domain, and the brand‑impersonation classification aligns with the page’s overt use of Solana branding and the promise of “auto‑trade” functionality, a classic lure for credential harvesting or transaction manipulation. Defenders should immediately add koltracking.com to URL and DNS blocklists, monitor outbound connections to the 104.21.17.212 address, and enforce strict content‑security policies that prevent unauthenticated script execution from this host. Continuous threat‑intel feeds should be consulted for any updates to the domain’s detection history, and organizations employing Solana‑related services should issue user alerts warning against unsolicited trade offers originating from this domain.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive