solana-sniper[.]xyz
“PumpFun Sniper Bot | Advanced Solana Trading Bot”
solana-sniper.xyz — Неперевірений. Уособлення бренду: Solana; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. Реєстратор: Porkbun.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of solana-sniper.xyz indicates a confirmed crypto scam targeting Solana users, operational as of July 22, 2026. The domain was registered on July 24, 2025, through registrar Porkbun LLC and is currently active with a 301 HTTP redirect status. Infrastructure analysis reveals Cloudflare hosting (AS13335) with nameservers karsyn.ns.cloudflare.com and robert.ns.cloudflare.com, resolving to IP 172.67.136.67 in the United States. The SSL certificate is issued by Google Trust Services (WE1), a common configuration for both legitimate and malicious sites.
The page title, 'PumpFun Sniper Bot | Advanced Solana Trading Bot,' explicitly references Solana and trading automation, aligning with the 'Crypto Scam' classification in available threat intelligence. Detection data shows the domain is flagged by two security blocklists, PhishDestroy and ScamSniffer, and three of 95 security vendors on VirusTotal. While the exact content of the site remains unanalyzed, the combination of brand impersonation, crypto-themed page title, and active blocklist presence confirms malicious intent. Defenders should treat this domain as high-risk.
The 301 redirect suggests it may be part of a larger redirection chain, though the final destination is not specified in available data. The use of Cloudflare nameservers and hosting is consistent with threat actors attempting to obscure origin infrastructure. Organizations should block the domain, IP 172.67.136.67, and monitor for related registrations under Porkbun LLC or similar Cloudflare-hosted infrastructure. Further investigation into the redirect target and any associated wallet addresses is recommended for complete mitigation.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога