iscan[.]solfam[.]cc
“iScans — Multi-Chain Portfolio Tracker”
Kaydedilmiş tespit
Gizleme uyarısı
- Gizleme türü
content_divergence- Gizleme puanı
- 2/6
Kanıt özeti
PhishDestroy identifies iscan.solfam.cc as an active generic phishing domain masquerading as a legitimate document-scanning portal. The infrastructure is currently unflagged by automated scanners, retaining a 17/95 detection score on VirusTotal as of seed a2d657. The domain was registered on April 15, 2026, resolving to IP 188.114.97.3 via a Let’s Encrypt SSL certificate and is hosted under NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar with historically low abuse oversight. No listings on public blocklists or trust-index downgrades have yet surfaced, indicating a first-stage campaign still in the evasion phase. This domain represents a generic phishing threat targeting users expecting document-processing services. Technical indicators include the April 15, 2026 creation date, IP 188.114.97.3 as the A record, and a recently issued Let’s Encrypt certificate serial common to fast-flux hosting. The registrar’s low reputation and zero VirusTotal detections highlight an elevated risk of successful user compromise before wider blacklisting occurs. The absence of current blocklist entries suggests a narrow targeting window where threat actors leverage fresh domains to harvest credentials or deliver malware under the guise of document workflows. Mitigation requires immediate DNS-level blocking of iscan.solfam.cc and the associated IP 188.114.97.3 across enterprise and endpoint layers. Users should treat any unexpected document-scanning prompts linking to this domain as malicious, avoiding data entry and reporting the lure to security teams. Network defenders should inspect SSL certificate telemetry for additional domains bearing the same Let’s Encrypt issuer fingerprint and proactively hunt for inbound TLS connections to 188.114.97.3 on port 443. Rapid takedown requests should be filed with NICENIC and Let’s Encrypt citing the domain’s fraudulent impersonation of document services and zero detections indicative of a live campaign.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260422-7F071B- Yakalanan sayfa başlığı
- iScans — Multi-Chain Portfolio Tracker
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Teknolojiler
6 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of iscan.solfam.cc · checked Apr 22, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin