Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@vercel.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
token-creator[.]justvanbloom[.]de
Pemeriksaan phishing dan keamanan token-creator.justvanbloom.de
“Solana Scaffold”
token-creator.justvanbloom.de — Terselubung · dapat dijangkau (HTTP 200). Peniruan identitas merek: Solana; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 2/91 (CRDF, Gridinsoft); cloaking observed; PhishDestroy score 86/100.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy identifies token-creator.justvanbloom.de as an active brand impersonation scam currently masquerading as OKX infrastructure. This domain, which presents a fraudulent interface under the guise of 'Solana Scaffold,' remains unblocked by conventional threat feeds despite its malicious intent. The campaign is classified as a high-confidence crypto drainer deployment, leveraging deceptive branding to harvest credentials and private keys from unsuspecting Solana users.
This domain resolves to IP 66.33.60.35 and operates under a valid Let's Encrypt SSL certificate, enhancing its phishing credibility. According to VirusTotal aggregation as of the latest scan, the domain remains undetected by 1 out of 95 participating security vendors, with no current listings on major blocklists. The domain was registered through Namecheap Inc., with creation timestamps indicating recent establishment, though exact creation date details remain obscured via privacy protection. Despite its low detection profile, behavioral analysis confirms active redirection pathways to wallet-draining scripts targeting Solana ecosystem participants.
Users encountering this domain should treat it as an immediate threat vector and refrain from any interaction, including loading scripts or connecting wallets. PhishDestroy recommends blocking the domain at the network perimeter via DNS sinkholing (66.33.60.35) and implementing browser-based protections to intercept similar typosquat variants. All Solana users are advised to verify URLs through official OKX channels and revoke any permissions granted to suspicious domains via tools like Phantom or Solflare's permission managers. Security teams should monitor for related infrastructure pivots and correlate logs against this IOC set for proactive containment.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 3 identified
Cloud platform for frontend deployment, optimized for Next.js.
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of token-creator.justvanbloom.de · checked Mar 25, 2026
Bukti & Laporan Eksternal
PD-20260325-7FA743 Recipient: abuse@vercel.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive