MALICIOUS — HIGH
Verifica phishing e sicurezza per claimsolrefund.com
claimsolrefund[.]
claimsolrefund.com was registered on March 12, 2026 through NiceNIC International Group Co., Limited and resolves to the Cloudflare edge address 104.21.70.69 (AS13335, United States).
- VirusTotal
- 4/94
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
claimsolrefund.com — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Solend; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 4/94 (alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 66/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
claimsolrefund.com was registered on March 12, 2026 through NiceNIC International Group Co., Limited and resolves to the Cloudflare edge address 104.21.70.69 (AS13335, United States). The domain is hosted behind Cloudflare, as indicated by the presence of Cloudflare Browser Insights, HSTS enforcement, and support for HTTP/3. The web server stack reports Node.js and Express, suggesting a custom application rather than a static site. SSL is provided by Let’s Encrypt with an E7 certificate, which is valid for the domain at the time of observation.
The only visible page title returned by the server is “Just a moment…”, a generic placeholder frequently used by Cloudflare when traffic is being challenged. The site is listed on the PhishDestroy blocklist and appears on one additional security blocklist, confirming that it has been identified as malicious by at least one trusted feed. VirusTotal scans show four of ninety‑four antivirus engines flagging the domain, reinforcing the suspicion of abuse. The domain is explicitly marked as impersonating the Solend brand and is classified as a crypto‑scam, indicating that any payload or request likely targets cryptocurrency assets.
The domain is currently offline, which may be the result of takedown actions or the operator disabling the site. No further content has been captured, and the exact phishing landing page or payload remains unknown. Defenders should continue to block the domain at DNS and proxy layers, monitor the associated IP range for related activity, and update threat‑intel feeds with the observed indicators. Additional analysis of any archived snapshots, TLS handshakes, or post‑offline activity could clarify the malicious infrastructure and help attribute the campaign.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 03:48:24 UTC
Tecnologie · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of claimsolrefund.com · checked Mar 12, 2026
Dati e relazioni esterneIndependent lookups and source reports
PD-20260312-09869B Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.