reallocations-solstice[.]xyz
“SOLSTICE | FLARES SEASON 1 REALLOCATION”
reallocations-solstice.xyz — İçerik kullanılamıyor (HTTP 502). Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 2/92 (alphaMountain.ai, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Kayıt kuruluşu: PDR.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies reallocations-solstice.xyz as a credential theft domain currently under investigation, posing an active risk to unsuspecting users. This domain employs deceptive tactics to mimic legitimate services, aiming to harvest login credentials and sensitive personal information. The threat actor behind this campaign has not yet been fully profiled, but the domain’s recent registration and lack of detection suggest a high potential for successful exploitation. Users interacting with this domain risk immediate account compromise, financial loss, or identity theft, making it critical to avoid engagement and report the domain to relevant authorities.
Technical indicators and domain intelligence reveal several red flags. The domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on May 16, 2026, and resolves to IP address 104.21.8.150. As of the latest scan, VirusTotal reports 2/95 detections, indicating no antivirus or security vendor has flagged it yet. The domain holds a valid SSL certificate issued by Let’s Encrypt, which may enhance its credibility in phishing lures. Given the absence of blocklist entries or trust score data, this domain remains unvetted and potentially malicious. The combination of a newly created domain, low detection rates, and a generic registrar raises significant concerns about its legitimacy.
To mitigate exposure to this credential theft threat, users and organizations must take immediate precautions. Avoid visiting reallocations-solstice.xyz or any linked subpages, and do not enter login credentials or personal data. Report the domain to your email provider, browser security teams, and cybersecurity platforms such as PhishDestroy or AbuseIPDB. Block the IP address 104.21.8.150 and the domain at the network firewall or DNS level to prevent internal access. Educate users about recognizing spoofed domains and the importance of verifying URLs before entering sensitive information. If credentials were entered, immediately reset passwords on affected accounts, enable multi-factor authentication, and monitor for unauthorized access or fraudulent activity. Proactive blocking and user awareness are essential to preventing credential theft and downstream account compromise.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of reallocations-solstice.xyz · checked May 16, 2026
Kanıtlar ve Dış Raporlar
PD-20260516-2C8DCE Recipient: abuse@publicdomainregistry.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin