solscantools[.]xyz
“Sol Scan Bot”
solscantools.xyz — Conteúdo indisponível (HTTP 502). Representação da marca: Solana; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 1/95 (Forcepoint ThreatSeeker); PhishDestroy score 55/100. Registrador: Go Daddy.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of solscantools.xyz indicates a confirmed brand‑impersonation infrastructure targeting the Solana ecosystem. The domain was registered on September 12, 2024 through Go Daddy, LLC and uses the default GoDaddy nameservers ns21.domaincontrol.com and ns22.domaincontrol.com. It resolves to IP address 185.199.109.153, which is owned by Fastly, Inc. (AS54113) and geolocated to the United States. No SSL certificate is present, meaning all traffic would be unencrypted if the site were reachable.
The page title returned by the server, "Sol Scan Bot," aligns with the documented scam type of a crypto scam and reinforces the intent to mimic legitimate Solana services. VirusTotal analysis shows that one out of ninety‑five security vendors flagged the domain, providing a minimal but tangible indication of malicious behavior. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy feed, confirming that at least one trusted anti‑phishing source has recognized it as harmful. Gridinsoft’s trust scoring system assigns a 0 / 100 rating, reflecting an extreme lack of reputation.
Current network status is offline, and the site does not return an active HTTP response. Nevertheless, the combination of brand impersonation, a low trust score, a flagged vendor detection, and inclusion on an active blocklist classifies the domain as elevated risk. Defenders should continue to block the domain at perimeter firewalls and DNS filters, monitor the associated IP for any re‑activation, and watch for new subdomains that may be created under the same registrar. Incident response teams should also consider adding the domain to internal threat intel repositories and share the indicator with broader threat‑sharing communities to prevent collateral victimization.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo