MALICIOUS — CRITICAL
rugsol.live की फ़िशिंग और सुरक्षा जाँच
rugsol[.]
This domain is flagged as a high-risk brand impersonation threat targeting Solana ecosystem users.
- VirusTotal
- 15/91
- Blocklists
- 2 · MetaMask, SEAL
- उपलब्धता
- सामग्री अनुपलब्ध · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
rugsol.live — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Solana; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 6 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. रजिस्ट्रार: Global Domain Group.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
This domain is flagged as a high-risk brand impersonation threat targeting Solana ecosystem users. The site, titled 'RugSol - Solana Token Scanner,' mimics legitimate Solana token scanning tools to deceive victims into disclosing wallet credentials or authorizing malicious transactions. Analysis indicates the domain was specifically designed to exploit trust in Solana’s brand, leveraging technical infrastructure associated with fraudulent cryptocurrency schemes. Infrastructure analysis reveals the domain was registered on February 26, 2026, through Global Domain Group LLC and resolves to IP address 193.233.75.119. Security vendors on VirusTotal flagged the domain as malicious, with 13 out of 95 detections. The domain appears on three security blocklists and is blocked by multiple cryptocurrency wallet extensions and anti-phishing tools. Technologies detected include Node.js, Ubuntu, React, Nginx, Next.js, and Webpack, suggesting a modern, server-side rendered frontend commonly used in phishing campaigns. The Gridinsoft trust score for this domain is 0/100, further confirming its malicious nature. Mitigation steps for this threat type include immediate blocking of the domain and associated IP address across all network security controls. Users should verify the legitimacy of any Solana-related tool by cross-referencing official Solana communication channels before interacting with third-party services. Cryptocurrency wallet users are advised to revoke any suspicious token approvals or connected applications linked to rugsol.live. Organizations should monitor for credential submissions or wallet interactions originating from this domain and conduct retrospective analysis to identify potential compromise. Security teams should update endpoint protection rules to detect and prevent access to known malicious infrastructure associated with this campaign.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
डेटा कवरेज13 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | auth-gateway-5934.vercel.app/solana?id=69b495d7ab4c1de49c2ebf98&bundle=1 |
audit | Hunting_JS_WebAssembly |
| DigiCert UltraDNS | ipfs.io |
malicious | Sinkholed |
| Cloudflare DNS | node2.irys.xyz |
malicious | Sinkholed |
| Hagezi Threat Feed | node2.irys.xyz |
malicious | Sinkholed |
| DNS4EU | node2.irys.xyz |
malicious | Sinkholed |
| DigiCert UltraDNS | cloudflare-dns.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% विश्वासUbuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com 100% विश्वासReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% विश्वासNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% विश्वासNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% विश्वासवायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
PD-20260429-AFB997 Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।