spl1-wvn[.]pages[.]dev
“Solana Token Creator”
证据摘要
PhishDestroy identifies the domain spl1-wvn.pages.dev as an active credential theft phishing site currently under investigation for generic phishing activities. The campaign is live and poses a direct risk to end users through social engineering tactics aimed at harvesting login credentials. As of the latest intelligence, no brand impersonation has been confirmed, but the domain remains active and should be treated as a high-risk threat vector. This domain was flagged by 0 of 95 VirusTotal vendors as of seed 22ca1a, indicating that signature-based detection has not yet caught up with the threat. The domain is registered through Cloudflare, Inc. and resolves to IP address 188.114.96.3. The SSL certificate is issued by Google Trust Services, which may lend an air of legitimacy to unsuspecting users. VirusTotal scans show zero detections at this time, reinforcing the need for proactive blocking mechanisms. Further investigation is required to determine the exact payload, lures, or targeted brands. The current status of spl1-wvn.pages.dev is active and under investigation. Users and organizations are strongly advised to block this domain at the DNS, firewall, or endpoint level immediately to prevent potential credential theft or malware delivery. Given the lack of detections on VirusTotal and the use of Cloudflare’s infrastructure, traditional security measures may not be sufficient. Implement domain reputation filtering, URL rewriting policies, and user awareness training to mitigate exposure. Monitor network traffic for connections to 188.114.96.3 and inspect SSL/TLS handshakes involving this IP. Report any observed activity to your security operations center and threat intelligence teams for further analysis and correlation with ongoing campaigns.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of spl1-wvn.pages.dev · checked Mar 25, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控