solbank-finances[.]pages[.]dev
“solbankfinance-io”
solbank-finances.pages.dev — 未验证. 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 4/91 (alphaMountain.ai, Fortinet, Gridinsoft, LevelBlue); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 76/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies solbank-finances.pages.dev as an active banking phishing domain designed to mimic legitimate financial institutions. This domain employs deceptive tactics to harvest sensitive banking credentials and financial data from unsuspecting users. The infrastructure suggests the use of a drainer kit, likely tailored to extract login details, transaction data, or personal identification information under the guise of a secure banking portal. No affiliation with established financial brands has been confirmed, indicating a probable spoofing campaign. This domain shows a VirusTotal detection score of 0/95, remaining unflagged despite its malicious nature. It resolves to IP 172.66.47.62 and is registered through Cloudflare, Inc., with an SSL certificate issued by Google Trust Services. The domain has been flagged on 2 security blocklists and is blocked by ScamSniffer and Enkrypt, highlighting its suspicious classification. The technical indicators suggest a rapidly evolving threat with evasion techniques, including the use of legitimate infrastructure (Cloudflare, Google Trust Services) to obscure malicious intent. As of current analysis, solbank-finances.pages.dev remains active and under investigation, posing a moderate to high risk to potential victims. Immediate response actions include continued monitoring, domain takedown requests, and user advisories. While detection rates remain low, users are strongly advised to avoid interacting with this domain. Remaining risk includes potential expansion into broader phishing campaigns or integration with additional malicious infrastructure. Enhanced scrutiny and proactive blocking mechanisms are recommended to mitigate further harm.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。