Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@key-systems.net.
The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
solana[.]wsbank[.]cc
“Solana Transfer Endpoint - Documentation”
solana.wsbank.cc — Доступен · доступ ограничен (HTTP 403). Олицетворение бренда: Solana; Тип мошенничества: Seed Phrase Theft. Сводка доказательств: VirusTotal 3/95 (alphaMountain.ai, Forcepoint ThreatSeeker, SOCRadar); PhishDestroy score 65/100. Регистратор: Key-Systems.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain solana.wsbank.cc is an active phishing site engaged in brand impersonation targeting the Solana cryptocurrency platform. It presents itself as a legitimate Solana service, specifically mimicking documentation pages under the title 'Solana Transfer Endpoint - Documentation', to deceive users into disclosing sensitive information such as wallet credentials. This site poses an elevated risk as a seed-phishing scam, though no crypto drainer kit has been identified at this time.
Technical analysis reveals that solana.wsbank.cc is flagged by 3 of 95 security vendors on VirusTotal, including alphaMountain.ai, Forcepoint ThreatSeeker, and SOCRadar. The domain is blocked by three security blocklists: PhishDestroy, MetaMask, and SEAL. It was registered through Key-Systems GmbH on February 21, 2026, and resolves to the IP address 172.67.198.138, hosted on Cloudflare's infrastructure (AS13335) in the US. The SSL certificate is issued by Google Trust Services / WE1, and the site employs HTTP/3 technology. Nameservers are jerome.ns.cloudflare.com and kia.ns.cloudflare.com, and the observed HTTP status is 403.
Users who may have interacted with solana.wsbank.cc should immediately revoke any token approvals and transfer funds to a new, secure wallet to prevent unauthorized access. If credentials were entered, change passwords on all associated accounts and enable two-factor authentication. Report the phishing domain to the impersonated brand (Solana) and submit it to platforms such as Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group to aid in broader mitigation efforts.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260118-9BD6A8 Recipient: abuse@key-systems.net Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание