sol-degenerates[.]netlify[.]app
“Site not found”
sol-degenerates.netlify.app — Contenu indisponible. Usurpation de l'identité de la marque : Solana; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 3/95 (ChainPatrol, alphaMountain.ai, Gridinsoft); PhishDestroy score 65/100. Bureau d’enregistrement: Netlify.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
On July 24, 2026, analysis of sol-degenerates.netlify.app identified a short-lived infrastructure that was hosting a crypto-related impersonation of the Solana brand. The site was provisioned on Netlify, as indicated by the registrar information and the presence of Netlify-specific technologies in the fingerprint, including HSTS enforcement. An SSL certificate issued by DigiCert Global G2 TLS RSA SHA256 2020 CA1 was observed, confirming the use of a valid public‑trusted certificate. HTTP probing returned a 404 status code and the page title "Site not found", suggesting the content was removed or never served a functional page. DNS resolution pointed to 63.176.8.218, an address owned by Amazon.com, Inc. (AS16509) located in Germany.
No authoritative nameserver records were returned (NS_NOT_FOUND), which is consistent with the domain being taken offline. VirusTotal scans reported three detections out of ninety‑five AV engines, and the domain appears on a single external blocklist. PhishDestroy has actively blocked the host, confirming that security‑focused services consider it malicious. The threat classification in the intelligence set labels the activity as a "Crypto Scam" that impersonates Solana, aligning with the observed brand target.
Given the limited surface—no active content, no login endpoints, and a single detection vector—current risk is elevated but mitigated by the offline status. However, the IP address is part of a cloud provider network; future reuse of the same host could enable re‑deployment of similar scams. Defenders should continue to monitor the IP range associated with AS16509 for new domains that resolve to the same address, enforce blocklist updates, and consider adding the domain hash to internal deny lists. Additional verification through real‑time DNS and SSL monitoring is recommended to detect any re‑activation.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif