regentsol[.]co
“Regent”
Riepilogo delle prove
The domain regentsol.co was observed as an offline host associated with a wallet/seed phishing campaign targeting the brand identified as "base". The site presented the page title "Regent" and employed the authoritative name servers dns1.webproserver.com and dns2.webproserver.com. Registration records show the domain was created on May 24, 2025, and it resolves to the IP address 192.3.190.186, which is allocated to ASN 36352 and hosted by HostPapa in the United States. Security scanning on VirusTotal recorded that sixteen of ninety‑five AV engines flagged the domain, indicating a moderate level of detection consensus.
Independent reputation services listed the domain on two blocklists, and the Gridinsoft trust score was recorded as zero out of one hundred, reflecting a high confidence of malicious intent. The TLS certificate presented was issued to PhishDestroy and references botadmin.destroy.tools, further linking the infrastructure to known phishing operations. The domain is currently blocked by PhishDestroy and ScamSniffer, and its risk level has been classified as elevated.
While the offline status prevents immediate interaction, the observable infrastructure suggests a reused phishing kit that leverages compromised hosting and fake SSL credentials to lure victims into submitting cryptocurrency wallet seeds. Defenders should continue to block the IP 192.3.190.186 and associated name servers, monitor for any re‑registration attempts, and incorporate the domain and its certificate identifiers into threat‑intel feeds. Additional scrutiny of any future domains issued by the same registrar or hosting provider is advisable, as the pattern of brand impersonation and wallet‑seed harvesting may reappear in new campaigns.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
9 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
VirusTotal
16 → 13
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
VirusTotal
13 → 14
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo