check-soneium[.]net
Resumen de las pruebas
Analysis as of July 25, 2026 indicates that check-soneium.net was registered on 21 February 2026 and is presently offline. The domain resolves to 104.21.45.82, an address owned by Cloudflare, Inc. (AS13335) located in the United States. The host is listed on five independent security blocklists, specifically PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura, confirming that multiple threat‑intelligence feeds have observed malicious activity associated with this name. VirusTotal has recorded detections from three of ninety‑three scanning engines, reinforcing the suspicion that the site was used for illicit purposes.
The TLS certificate presented on the service is identified as “WE1”, which does not correspond to a publicly trusted authority and may have been self‑signed or issued by a low‑reputation CA, a common characteristic of short‑lived phishing infrastructure. Because the site is currently taken offline, direct content inspection is not possible, and the page title, brand targeting, or specific phishing kit details remain unknown. Nevertheless, the convergence of recent domain creation, Cloudflare‑based hosting, multiple blocklist listings, and positive VirusTotal detections provides sufficient confidence to classify the domain as a generic phishing vector.
Defenders should update internal URL filtering policies to block check-soneium.net and any subdomains, enforce DNS sink‑holing for the resolved IP address, and monitor outbound traffic for connections to 104.21.45.82. Threat‑intel teams should also add the domain to indicator‑of‑compromise (IOC) feeds and correlate any user‑initiated requests with authentication logs to detect possible credential harvesting attempts. Continuous re‑evaluation is advised in case the domain is re‑activated or the hosting provider changes its content.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
6 fuentes externas supervisadas Sin coincidencias
Inteligencia forense
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.