# docssolflare.wixstudio.com — MALICIOUS — Crypto Drainer (Solana Drainer) > Malicious domain docssolflare.wixstudio.com uses a Solana drainer kit to steal crypto. Resolves to IP 34.144.206.118. ## Summary PhishDestroy identifies docssolflare.wixstudio.com as a newly active Solana cryptocurrency drainer posing immediate risk to wallet security. This Wix-hosted domain resolves to 34.144.206.118, where attackers deploy automated scripts to siphon funds from unsuspecting users. The payload is distributed via spoofed documents or service pages, tricking victims into connecting their wallets under false pretenses. The infrastructure behind this threat shows minimal detection despite clear malicious intent. VirusTotal analysis reveals zero out of 95 security engines currently flag the domain, while the SSL certificate is issued by Let’s Encrypt—often abused for evasion. The domain remains unblocked across major threat intelligence feeds, increasing exposure to potential victims. Historical records indicate this domain is recently registered, further suggesting opportunistic use in current campaigns. Anyone who accessed docssolflare.wixstudio.com should immediately revoke any wallet connections shown in browser extension transaction history. Disable unused browser extensions, clear cached credentials, and scan devices with updated antivirus tools. Report the domain to your security team and consider rotating wallet private keys if funds were ever exposed. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: unknown (HTTP ?) - Drainer type: Solana Drainer ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 34.144.206.118 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/docssolflare.wixstudio.com - PhishDestroy: https://phishdestroy.io/domain/docssolflare.wixstudio.com/ - LLM endpoint: https://phishdestroy.io/domain/docssolflare.wixstudio.com/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/docssolflare.wixstudio.com/ Last updated: 2026-04-01