iscan[.]solfam[.]cc
“iScans — Multi-Chain Portfolio Tracker”
iscan.solfam.cc — Encoberto · alcançável (HTTP 502). Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 95/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies iscan.solfam.cc as an active generic phishing domain masquerading as a legitimate document-scanning portal. The infrastructure is currently unflagged by automated scanners, retaining a 17/95 detection score on VirusTotal as of seed a2d657. The domain was registered on April 15, 2026, resolving to IP 188.114.97.3 via a Let’s Encrypt SSL certificate and is hosted under NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar with historically low abuse oversight. No listings on public blocklists or trust-index downgrades have yet surfaced, indicating a first-stage campaign still in the evasion phase. This domain represents a generic phishing threat targeting users expecting document-processing services. Technical indicators include the April 15, 2026 creation date, IP 188.114.97.3 as the A record, and a recently issued Let’s Encrypt certificate serial common to fast-flux hosting. The registrar’s low reputation and zero VirusTotal detections highlight an elevated risk of successful user compromise before wider blacklisting occurs. The absence of current blocklist entries suggests a narrow targeting window where threat actors leverage fresh domains to harvest credentials or deliver malware under the guise of document workflows. Mitigation requires immediate DNS-level blocking of iscan.solfam.cc and the associated IP 188.114.97.3 across enterprise and endpoint layers. Users should treat any unexpected document-scanning prompts linking to this domain as malicious, avoiding data entry and reporting the lure to security teams. Network defenders should inspect SSL certificate telemetry for additional domains bearing the same Let’s Encrypt issuer fingerprint and proactively hunt for inbound TLS connections to 188.114.97.3 on port 443. Rapid takedown requests should be filed with NICENIC and Let’s Encrypt citing the domain’s fraudulent impersonation of document services and zero detections indicative of a live campaign.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Latest Classified Outcome 2026-08-13 03:22:42 UTC
Tecnologias · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% de confiançaVue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% de confiançaCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of iscan.solfam.cc · checked Apr 22, 2026
Evidências e relatórios externos
PD-20260422-7F071B Recipient: abuse@nicenic.net Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo