MALICIOUS — CRITICAL
solbot1[.]cc
Analysis of solbot1.cc shows a newly registered domain (creation date 21 May 2026) that is actively serving HTTP content (status 200) behind Cloudflare infrastructure (IP 104.21.87.204, CA location).
- VirusTotal
- 9/91
- Blocklists
- 1 · ScamSniffer
- Доступність
- Останній відомий активний · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
solbot1.cc — Останній відомий активний (HTTP 200). Зведення доказів: VirusTotal 9/91 (alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet); 1 external blocklist match (ScamSniffer); PhishDestroy score 87/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
Is solbot1.cc a phishing site?
Security analysis of solbot1.cc covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
Analysis of solbot1.cc shows a newly registered domain (creation date 21 May 2026) that is actively serving HTTP content (status 200) behind Cloudflare infrastructure (IP 104.21.87.204, CA location). The domain uses a Let's Encrypt certificate (E8) and is delegated to Cloudflare nameservers gigi.ns.cloudflare.com and matt.ns.cloudflare.com. Reputation data is poor: Gridinsoft assigns a trust score of 0/100, the domain appears on two security blocklists, and it has been flagged by the PhishDestroy and ScamSniffer blocklists. AlienVault OTX lists the domain in one threat pulse, and VirusTotal reports three detections out of 91 scanned vendors. Registration was performed through Gname.com Pte. Ltd., a registrar often associated with disposable or low‑cost registrations. The combination of a fresh registration, zero trust score, multiple blocklist listings, and positive detections on VirusTotal aligns with the high‑risk generic phishing classification. Uncertainty remains regarding the specific payload or victim targeting, as no page content or phishing kit details are available. Defenders should block or sinkhole the domain at the network perimeter, monitor DNS queries for the associated IP and nameservers, and include the domain in threat‑intel feeds. Continuous re‑scanning on VirusTotal or similar services is advised to capture any evolving indicators.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Аналіз конфігурації сайту
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.