eligibility[.]bonksolana[.]xyz
eligibility.bonksolana.xyz — Ошибка сервера (HTTP 502). Олицетворение бренда: Solana; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 2/95 (Forcepoint ThreatSeeker, Trustwave); PhishDestroy score 61/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
eligibility.bonksolana.xyz was observed as a malicious domain targeting the Solana brand. The domain was registered on September 09, 2025 through NiceNIC International Group Co., Limited and resolves to the Cloudflare edge address 104.21.31.117, which belongs to ASN 13335 (Cloudflare, Inc.) located in the United States. No SSL certificate is presented for the host, and the HTTP response currently returns a generic page with the title “Just a moment…”. The site has been classified as a crypto‑scam and is listed by PhishDestroy as blocked. VirusTotal analysis shows that two of ninety‑five scanned engines flagged the domain, indicating a low but non‑zero detection rate.
Independent reputation services assign extremely low trust scores: Gridinsoft rates it 0/100, while Scamadviser reports a 1/100 rating. The domain appears on a single security blocklist, reinforcing the indication of malicious activity. Nameservers are michael.ns.cloudflare.com and robin.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure. The available evidence confirms the domain’s intent to impersonate Solana, yet the exact payload and user‑facing content remain unverified because the site is currently offline. No TLS certificate, no visible login page, and only the placeholder title have been captured.
Consequently, analysts cannot determine whether the site hosted phishing forms, malicious binaries, or redirect chains. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence of the host, and add the IP address 104.21.31.117 to threat intel feeds. Periodic rescans with VirusTotal or similar services are advised to capture any changes in detection status. Updating endpoint and web‑gateway filters with the observed indicators of compromise will mitigate exposure to this low‑trust, brand‑impersonation campaign.
Сигналы безопасности
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: bonksolana.xyz
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain bonksolana.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-21 02:55:52 UTC
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание