sol-degenerates[.]netlify[.]app
“Site not found”
sol-degenerates.netlify.app — 内容不可用. 品牌冒充:Solana; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 3/95 (ChainPatrol, alphaMountain.ai, Gridinsoft); PhishDestroy score 65/100. 注册商: Netlify.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
On July 24, 2026, analysis of sol-degenerates.netlify.app identified a short-lived infrastructure that was hosting a crypto-related impersonation of the Solana brand. The site was provisioned on Netlify, as indicated by the registrar information and the presence of Netlify-specific technologies in the fingerprint, including HSTS enforcement. An SSL certificate issued by DigiCert Global G2 TLS RSA SHA256 2020 CA1 was observed, confirming the use of a valid public‑trusted certificate. HTTP probing returned a 404 status code and the page title "Site not found", suggesting the content was removed or never served a functional page. DNS resolution pointed to 63.176.8.218, an address owned by Amazon.com, Inc. (AS16509) located in Germany.
No authoritative nameserver records were returned (NS_NOT_FOUND), which is consistent with the domain being taken offline. VirusTotal scans reported three detections out of ninety‑five AV engines, and the domain appears on a single external blocklist. PhishDestroy has actively blocked the host, confirming that security‑focused services consider it malicious. The threat classification in the intelligence set labels the activity as a "Crypto Scam" that impersonates Solana, aligning with the observed brand target.
Given the limited surface—no active content, no login endpoints, and a single detection vector—current risk is elevated but mitigated by the offline status. However, the IP address is part of a cloud provider network; future reuse of the same host could enable re‑deployment of similar scams. Defenders should continue to monitor the IP range associated with AS16509 for new domains that resolve to the same address, enforce blocklist updates, and consider adding the domain hash to internal deny lists. Additional verification through real‑time DNS and SSL monitoring is recommended to detect any re‑activation.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。