# PhishDestroy threat dossier — sologenic-migrate.org ================================================================ Fetched: 2026-05-16 21:11:29 UTC Canonical: https://phishdestroy.io/domain/sologenic-migrate.org/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 49/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/95 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Gridinsoft, LevelBlue, Webroot URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.144.114 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Key-Systems GmbH Nameservers: ben.ns.cloudflare.com, brynne.ns.cloudflare.com Registered: 2026-05-08 Page title: Sologenic is now TX — Final $SOLO to $TX Migration ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-16 21:15:12 UTC (by PhishDestroy tracker) First reported: 2026-05-16 18:16:55 UTC (abuse notice filed) Last verified: 2026-05-16 21:45:05 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e31fd-d22f-717a-b434-ee06aa413ab0/ URLQuery: https://urlquery.net/report/0e9f66c6-fa91-42dc-b584-df408714c2f3 Wayback Machine: https://web.archive.org/web/*/sologenic-migrate.org crt.sh CT logs: https://crt.sh/?q=%25.sologenic-migrate.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=sologenic-migrate.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/sologenic-migrate.org URLhaus: https://urlhaus.abuse.ch/host/sologenic-migrate.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-16 21:16:51 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies sologenic-migrate.org as an active crypto drainer campaign impersonating the Sologenic platform. The domain is designed to lure victims into connecting their cryptocurrency wallets under the guise of an account migration portal. Threat actors leverage the trusted Sologenic branding to increase credibility and exploit user trust, enabling unauthorized fund transfers via malicious smart contracts embedded in the fake interface. Domain sologenic-migrate.org exhibits multiple red flags consistent with malicious infrastructure. It was registered on May 08, 2026, through Key-Systems GmbH, and resolves to IP address 172.67.144.114. VirusTotal analysis shows a 4/95 detection rate among security vendors, while Google Safe Browsing has flagged the domain. Additionally, the domain is listed on one public blocklist, and it utilizes a legitimate SSL certificate issued by Let’s Encrypt to enhance its appearance of authenticity. The domain name itself is crafted to appear official, using the “-migrate” suffix to imply a necessary platform transition. This domain remains active as of the latest intelligence cycle. It has been blocked by ScamSniffer, indicating prior detection by fraud prevention tools. While current status shows active operation, response actions include domain blacklisting and IP-based blocking by security platforms. However, the risk remains elevated due to the ongoing use of impersonation tactics, the short domain age suggesting opportunistic deployment, and the potential for continued abuse under trusted branding. Users are strongly advised to verify any Sologenic-related communication through official channels and use tools like PhishDestroy to confirm domain legitimacy before interacting. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260516-38849E Favicon MD5: 21c183b1e9aa082ec5daca742179d21f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/sologenic-migrate.org/ JSON API: https://api.destroy.tools/v1/check?domain=sologenic-migrate.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 150,336 domains (30,766 alive under monitoring, 118,107 confirmed takedowns/dead). Site: https://phishdestroy.io