MALICIOUS — HIGH
justrelay[.]fun
This domain, justrelay.fun, presents a brand impersonation threat targeting Solana users by mimicking a legitimate wallet messenger service.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
justrelay.fun — Contenuto non disponibile (HTTP 404). Simulazione del marchio: Solana; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Registrar: GoDaddy.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
This domain, justrelay.fun, presents a brand impersonation threat targeting Solana users by mimicking a legitimate wallet messenger service. The site displays the page title 'Relay - Solana Wallet Messenger,' suggesting an attempt to deceive users into entering sensitive wallet credentials or private keys under the guise of a trusted communication platform. Such impersonation schemes are commonly used to facilitate cryptocurrency theft by harvesting authentication details from unsuspecting victims. Analysis indicates the domain was registered on March 30, 2026, through GoDaddy.com, LLC, and resolved to the IP address 34.111.179.208, hosted on Google Cloud infrastructure. It appears on one security blocklist and has been referenced in eight threat intelligence pulses on AlienVault OTX, signaling prior detection by security researchers. Despite these indicators, the domain currently shows 0/95 detections on VirusTotal, meaning it has not yet been flagged by most antivirus or URL scanning engines. The SSL certificate is issued by Let's Encrypt, a common but neutral finding, while detected technologies include Node.js, React, Next.js, and Google Cloud CDN, consistent with modern web applications. Users who visited justrelay.fun should assume potential exposure of wallet credentials or other sensitive data. Immediate actions include revoking access to any connected wallets, generating new private keys, and monitoring accounts for unauthorized transactions. If cryptocurrency was transferred to an unknown address, report the incident to the relevant blockchain explorer and consider filing a complaint with local cybercrime authorities. Given the domain’s current offline status, further interaction is unlikely, but vigilance for similar phishing attempts is advised.
Copertura dei dati13 recorded checks
Indicatori di sicurezza
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 9 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
JavaScript library for building user interfaces with component-based architecture.
Suite of cloud computing services running on Google infrastructure.
React framework for production with hybrid static and server rendering.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Content delivery network built on Google global edge infrastructure.
Module bundler for modern JavaScript applications.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of justrelay.fun · checked Jun 26, 2026
Dati e relazioni esterneIndependent lookups and source reports
PD-20260330-8C28D3 Recipient: abuse@godaddy.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.