MALICIOUS — CRITICAL
Verifica phishing e sicurezza per suliend.pw
suliend[.]
Analysis of the domain suliend.pw indicates that it was registered on February 27, 2026 through NameSilo, LLC and is currently hosted on Cloudflare infrastructure (AS13335).
- VirusTotal
- 5/94
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
suliend.pw — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Solend; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 5/94 (ADMINUSLabs, alphaMountain.ai, G-Data, SOCRadar, Sophos); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. Registrar: NameSilo.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
Analysis of the domain suliend.pw indicates that it was registered on February 27, 2026 through NameSilo, LLC and is currently hosted on Cloudflare infrastructure (AS13335). The domain resolves to IP address 172.67.209.94, which is geolocated to the United States and serviced by the Cloudflare nameservers isla.ns.cloudflare.com and razvan.ns.cloudflare.com. No TLS certificate was observed, meaning the site served HTTP without encryption. The page title returned by the HTTP response is "Phase 2 Distribution," which does not directly reference the targeted brand but aligns with the reported scam type of brand impersonation.
The site is listed on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal scans show that five of ninety‑four security vendors flagged the domain as malicious, reinforcing the suspicion of abuse. The intelligence identifies the impersonated brand as Solend, confirming the intent to deceive users of that service.
As of the report date, July 22, 2026, the domain has been taken offline, but the historical footprint suggests that threat actors may reactivate the same infrastructure or register similar domains. Defenders should continue to block the domain and its IP at perimeter defenses, monitor for re‑use of the associated Cloudflare IP range, and update detection rules to include the page title "Phase 2 Distribution" as an indicator of compromise. Further investigation is needed to determine whether additional payloads or command‑and‑control endpoints were associated with the site before takedown, and whether the same registrar or nameserver pattern recurs in other observed campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
PD-20260227-66682C Recipient: abuse@namesilo.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.