Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@vercel.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
token-creator[.]justvanbloom[.]de
“Solana Scaffold”
token-creator.justvanbloom.de — Прикритий · доступний (HTTP 200). Уособлення бренду: Solana; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2/91 (CRDF, Gridinsoft); cloaking observed; PhishDestroy score 86/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies token-creator.justvanbloom.de as an active brand impersonation scam currently masquerading as OKX infrastructure. This domain, which presents a fraudulent interface under the guise of 'Solana Scaffold,' remains unblocked by conventional threat feeds despite its malicious intent. The campaign is classified as a high-confidence crypto drainer deployment, leveraging deceptive branding to harvest credentials and private keys from unsuspecting Solana users.
This domain resolves to IP 66.33.60.35 and operates under a valid Let's Encrypt SSL certificate, enhancing its phishing credibility. According to VirusTotal aggregation as of the latest scan, the domain remains undetected by 1 out of 95 participating security vendors, with no current listings on major blocklists. The domain was registered through Namecheap Inc., with creation timestamps indicating recent establishment, though exact creation date details remain obscured via privacy protection. Despite its low detection profile, behavioral analysis confirms active redirection pathways to wallet-draining scripts targeting Solana ecosystem participants.
Users encountering this domain should treat it as an immediate threat vector and refrain from any interaction, including loading scripts or connecting wallets. PhishDestroy recommends blocking the domain at the network perimeter via DNS sinkholing (66.33.60.35) and implementing browser-based protections to intercept similar typosquat variants. All Solana users are advised to verify URLs through official OKX channels and revoke any permissions granted to suspicious domains via tools like Phantom or Solflare's permission managers. Security teams should monitor for related infrastructure pivots and correlate logs against this IOC set for proactive containment.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Cloud platform for frontend deployment, optimized for Next.js.
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of token-creator.justvanbloom.de · checked Mar 25, 2026
Докази та зовнішні звіти
PD-20260325-7FA743 Recipient: abuse@vercel.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога