PhishDestroy first observed jpool-dex.net on Jul 28, 2026. Stored content metadata identifies Solana as the apparent target. The captured page title is “JPool DEX — #1 Solana Liquid Staking”. Stored page analysis classifies the content as impersonation. Current evidence score: 69/100 (high).
One source contains a positive finding: VirusTotal. VirusTotal recorded 3 detections among 91 engines: CRDF, Gridinsoft, SOCRadar on Aug 7, 2026 at 02:10 UTC. Non-positive and contextual checks: On Jul 28, 2026 at 19:11 UTC, AlienVault OTX listed 4 community pulse references (not vendor detections); Google Safe Browsing returned no flag. The separate external-blocklist snapshot contained no matches on Aug 8, 2026 at 10:20 UTC. URLQuery recorded no positive detection on Jul 28, 2026 at 19:41 UTC. URLScan completed without a malicious verdict (score 0) on Jul 29, 2026 at 02:23 UTC.
HTTP 200 was recorded on Aug 8, 2026 at 10:30 UTC. Registration records for the domain list Fewmoretaps OU d/b/a Trustname.com as the registrar and Jul 23, 2026 as the creation date. Registration preceded first observation by 5 days. At collection time, the hostname resolved to 186.2.175.109 on AS59692 (IQWeb FZ-LLC). The recorded endpoint location is Belmopan, BZ. The stored server header is ddos-guard. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Oct 21, 2026; checked Jul 28, 2026 at 19:02 UTC.
Stored content provides classification context, but only one source contains a positive finding.