sol-join[.]online
Phishing and security check for sol-join.online
PhishDestroy first observed sol-join.online on Feb 5, 2026. A positive finding was recorded by VirusTotal. Evidence score: 97/100.
VirusTotal recorded 14 detections among 93 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet on May 9, 2026 at 22:14 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Feb 5, 2026 at 12:41 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:24 UTC; content was unavailable. Registration records list PDR Ltd. d/b/a PublicDomainRegistry.com as the registrar. At collection time, the domain resolved to 188.114.96.3. Collected metadata identifies Solana as the apparent target. PhishDestroy classified the observed content as Crypto Scam. DOM analysis completed on Apr 23, 2026 at 19:20 UTC; stored DOM score 0/100. IoC extraction completed on Aug 2, 2026 at 04:14 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysisJun 23, 2026
This report analyzes the domain sol-join.online, which impersonates the Solana cryptocurrency brand. The site poses a threat by attempting to trick users into connecting cryptocurrency wallets or sharing private keys, leading to asset theft.
Technical analysis reveals that VirusTotal flagged the site with 14 detections out of 95 vendors, including ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, and CyRadar. The domain is listed on one blocklist. It was registered on 2026-02-21 through PDR Ltd. d/b/a PublicDomainRegistry.com, hosted on IP 188.114.96.3 (US, AS13335 Cloudflare, Inc.), and uses nameservers andronicus.ns.cloudflare.com and lina.ns.cloudflare.com. No SSL certificate was detected.
The domain is currently down or offline. Based on the GridinSoft trust score of 0/100, the high detection rate, and the cryptocurrency scam branding, the risk level is critical. Users should avoid any interaction with this domain.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
ICANN Got Paid. Accountability Did Not Arrive.
For this gTLD, the registrar above operates under an ICANN contract. ICANN collects annual, variable and transaction-based fees tied to registrations, renewals and transfers.
Accreditation: monetized. Accountability: please check back later.
Then the magic starts: ICANN writes RAA §3.18, the registrar investigates abuse inside its own customer base, and victims deliver the evidence for free while every layer waits for someone else to act. If that makes victims feel safer, excellent—the invoice worked.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
About This Report: sol-join.online
Stored evidence snapshot. Source timestamps appear where available.
VirusTotal detections for sol-join.online: 14 (Aug 7, 2026).
submit an appeal or review the FAQ page.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive