regentsol[.]co
“Regent”
Сводка доказательств
The domain regentsol.co was observed as an offline host associated with a wallet/seed phishing campaign targeting the brand identified as "base". The site presented the page title "Regent" and employed the authoritative name servers dns1.webproserver.com and dns2.webproserver.com. Registration records show the domain was created on May 24, 2025, and it resolves to the IP address 192.3.190.186, which is allocated to ASN 36352 and hosted by HostPapa in the United States. Security scanning on VirusTotal recorded that sixteen of ninety‑five AV engines flagged the domain, indicating a moderate level of detection consensus.
Independent reputation services listed the domain on two blocklists, and the Gridinsoft trust score was recorded as zero out of one hundred, reflecting a high confidence of malicious intent. The TLS certificate presented was issued to PhishDestroy and references botadmin.destroy.tools, further linking the infrastructure to known phishing operations. The domain is currently blocked by PhishDestroy and ScamSniffer, and its risk level has been classified as elevated.
While the offline status prevents immediate interaction, the observable infrastructure suggests a reused phishing kit that leverages compromised hosting and fake SSL credentials to lure victims into submitting cryptocurrency wallet seeds. Defenders should continue to block the IP 192.3.190.186 and associated name servers, monitor for any re‑registration attempts, and incorporate the domain and its certificate identifiers into threat‑intel feeds. Additional scrutiny of any future domains issued by the same registrar or hosting provider is advisable, as the pattern of brand impersonation and wallet‑seed harvesting may reappear in new campaigns.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
9 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
VirusTotal
16 → 13
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
VirusTotal
13 → 14
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание