MALICIOUS — CRITICAL
web-solchainfix[.]pages[.]dev
PhishDestroy identifies web-solchainfix.pages.dev as an active crypto drainer phishing domain designed to steal cryptocurrency assets from unsuspecting users.
- VirusTotal
- 12/94
- Blocklists
- 1 · ScamSniffer
- Disponibilité
- Accessible · accès restreint · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
web-solchainfix.pages.dev — Accessible · accès restreint (HTTP 403). Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 12/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Google Safe Browsing flagged; 1 external blocklist match (ScamSniffer); PhishDestroy score 91/100. Bureau d’enregistrement: Cloudflare.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
PhishDestroy identifies web-solchainfix.pages.dev as an active crypto drainer phishing domain designed to steal cryptocurrency assets from unsuspecting users. This domain leverages deceptive branding (Solana/Chainfix) to impersonate legitimate services, tricking victims into connecting wallets or entering private keys. The infrastructure is built on a Cloudflare Pages deployment, exploiting the platform’s legitimacy to evade detection while hosting malicious JavaScript payloads for wallet drainer operations.
Technical indicators confirm this domain as a high-risk threat. VirusTotal reports a detection score of 12/95 security vendors (12.6% coverage), while Google Safe Browsing classifies it as an active phishing domain. The domain resolves to IP 188.114.96.3 (Cloudflare ASN) and is registered through Cloudflare, Inc., with creation timing aligning with recent phishing campaigns. This aligns with a growing trend of crypto drainer phishing sites abusing reputable hosting/CDN services to bypass traditional security controls.
This domain remains active as of the latest analysis, with Cloudflare’s infrastructure complicating takedown efforts. Immediate user action includes avoiding the domain and checking connected wallets for unauthorized transactions. Security teams should block the IP (188.114.96.3) and domain at network/firewall levels. Remaining risk is high due to the drainer’s active status, with potential for further abuse of Cloudflare’s ecosystem. Users are advised to verify URLs via reputable threat databases and avoid interacting with unsolicited crypto-related links.
Couverture des données12 recorded checks
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 5 identified
Popular CSS framework for responsive, mobile-first web development.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of web-solchainfix.pages.dev · checked Mar 26, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.