# PhishDestroy threat dossier — mintsol.dev ================================================================ Fetched: 2026-08-01 16:31:40 UTC Canonical: https://phishdestroy.io/domain/mintsol.dev/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 68/100 (PhishDestroy scoring — see methodology below) Scam classification: Wallet/Seed Phishing Targeted brand: orca (and: raydium, solana) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/95 security vendors flagged this domain Flagging vendors: SOCRadar Public blocklists: listed on 1 independent blocklist Victim re-reports (public form): 1 ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 57.129.97.29 (DE, Frankfurt am Main) ASN: ASAS16276 OVH OVH SAS, FR Hosting org: AS16276 OVH SAS Registrar: SD-onenetwork (ASN: 16276) Nameservers: blair.ns.cloudflare.com, bryce.ns.cloudflare.com Page title: Mintsol — Create Your Solana Token ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: none Status: INVALID chain ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-02-25 02:39:27 UTC (by PhishDestroy tracker) First reported: 2025-11-20 16:14:48 UTC (abuse notice filed) Last verified: 2026-08-01 16:21:41 UTC Neutralised: 2026-02-23 03:15:03 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019aa20b-b20c-71c5-896b-523efcbccb70/ Wayback Machine: https://web.archive.org/web/*/mintsol.dev crt.sh CT logs: https://crt.sh/?q=%25.mintsol.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=mintsol.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/mintsol.dev URLhaus: https://urlhaus.abuse.ch/host/mintsol.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-08 16:07:12 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] mintsol.dev Phishing Intelligence Report - PhishDestroy mintsol.dev is a phishing domain involved in brand impersonation targeting the Orca brand. The site was used in a wallet_connect_phish scam and is currently taken offline. This domain poses an elevated risk to users seeking safe platforms related to Solana token creation and Orca services. Technical indicators for mintsol.dev include detection by 1 of 95 VirusTotal security vendors, including SOCRadar. The domain is registered through SD-onenetwork (ASN: 16276) and resolves to IP address 57.129.97.29 located in Germany (AS16276 OVH SAS). It appears on one security blocklist, PhishDestroy, and has no SSL certificate issued. The observed page title was 'Mintsol — Create Your Solana Token'. Nameservers used are blair.ns.cloudflare.com and bryce.ns.cloudflare.com. Users exposed to mintsol.dev phishing attempts should take immediate safety steps. For wallet-related scams, it is advised to revoke all token approvals and transfer funds to a new wallet. Monitoring accounts for suspicious activity is crucial. To report this scam or seek assistance, users can contact relevant cybersecurity authorities or use platforms like PhishDestroy. Changing passwords and enabling two-factor authentication are recommended for any linked accounts to prevent credential compromise. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/mintsol.dev/ JSON API: https://api.destroy.tools/v1/check?domain=mintsol.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 177,635 domains (72,461 alive under monitoring, 27,318 confirmed neutralized). Site: https://phishdestroy.io