solstorm-com[.]pages[.]dev
Verifica phishing e sicurezza per solstorm-com.pages.dev
“SOLSTORM”
solstorm-com.pages.dev — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Fortinet, Gridinsoft, LevelBlue); URLQuery 1 alert; 1 external blocklist match (ScamSniffer); PhishDestroy score 80/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies the domain solstorm-com.pages.dev as an active crypto drainer posing as a legitimate service. This domain is currently engaged in malicious activities aimed at deceiving users into connecting cryptocurrency wallets, with the ultimate goal of draining funds under false pretenses. The threat remains active and requires immediate attention from security teams and affected users.
This domain was flagged by 1 of 95 VirusTotal vendors and appears on a single security blocklist maintained by ScamSniffer. The domain resolves to the IP address 188.114.96.3 and is registered through Cloudflare, Inc. While the exact registration date is not provided in the available intelligence, the domain operates under a Google Trust Services SSL certificate, which adds a deceptive layer of legitimacy. The minimal detection rate and single blocklist presence suggest this campaign may be newly emerged or highly targeted, complicating early-stage mitigation efforts.
The current status of this domain remains active, with no evidence of takedown or remediation at this time. Security teams are advised to block this domain at the network perimeter and update firewall rules accordingly. Users are strongly urged to avoid interacting with this domain or any associated links and to verify the legitimacy of websites before connecting cryptocurrency wallets. Additionally, organizations should monitor for any new domains mimicking legitimate services and consider deploying advanced threat intelligence solutions to detect similar campaigns early.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | solstorm-com.pages.dev/c04f83c984ed122ad8.js |
audit | Hunting_JS_WebAssembly |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Confidenza al 100%Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.