# PhishDestroy threat dossier — solana.traxr.pro ================================================================ Fetched: 2026-06-27 04:31:02 UTC Canonical: https://phishdestroy.io/domain/solana.traxr.pro/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer Targeted brand: Solana Wallet drainer: Solana Drainer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/94 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 185.98.208.131 (SK, Cífer) ASN: AS30929 GOLEM TECH s.r.o. Hosting org: GOLEM TECH s.r.o. Registrar: NameCheap, Inc. Nameservers: ["dns1.registrar-servers.com", "dns2.registrar-servers.com"] Registered: 2026-03-29 Page title: TRAXR-SOLANA | Pool Risk Intelligence ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-27 Status: INVALID chain Fingerprint: 58649680b6818764c355e4bee6500394d82532b4c8b23b89363c5c35f715d1bf ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-29 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-03-29 19:48:42 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-03-29 16:49:02 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-06-27 04:20:35 UTC Neutralised: 2026-04-26 18:22:49 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d3a7e-1f63-73cd-9dff-6e382a3bfea7/ URLQuery: https://urlquery.net/report/79a91a19-07ce-47dc-a6da-f1efdcb61575 Wayback Machine: https://web.archive.org/web/*/solana.traxr.pro crt.sh CT logs: https://crt.sh/?q=%25.solana.traxr.pro Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=solana.traxr.pro AlienVault OTX: https://otx.alienvault.com/indicator/domain/solana.traxr.pro URLhaus: https://urlhaus.abuse.ch/host/solana.traxr.pro/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-03-29 19:49:22 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies solana.traxr.pro as an active Solana-branded crypto drainer domain designed to deceive users into connecting cryptocurrency wallets and approve malicious transactions that siphon digital assets. The site impersonates the legitimate Solana blockchain network using a fraudulent domain imbued with a drainer kit specifically engineered for Solana-based wallets. Users attempting to interact with any ‘Solana’-branded service via this domain risk immediate financial loss upon wallet connection or transaction approval. solana.traxr.pro resolves to IP address 185.98.208.131 and is secured with a valid Let's Encrypt SSL certificate to enhance perceived legitimacy. As of the latest scan, the domain shows 0 detections out of 95 engines on VirusTotal, indicating it remains undetected by most antivirus and security platforms. The domain was registered under a privacy-protected registrar and is currently unlisted on Google Safe Browsing and major threat blocklists, amplifying its stealth and reach. This combination of evasion techniques suggests an advanced, low-signature campaign targeting Solana users. This domain remains active and constitutes a high-risk threat to users engaging with Solana-related services. Immediate defensive actions include blocking the domain at network and endpoint levels, flagging the associated IP range, and updating security policies to detect drainer activity via heuristic transaction monitoring. Users should verify all Solana-related domains against official sources and avoid connecting wallets to unfamiliar links. While current detections are low, rapid escalation is expected. Remaining risk is high due to active deployment and the irreversible nature of cryptocurrency theft. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260329-B8CE5E Favicon MD5: 70a74c84db4fff952551ebb44c8ef082 TLS cert SHA-256: 58649680b6818764c355e4bee6500394d82532b4c8b23b89363c5c35f715d1bf ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/solana.traxr.pro/ JSON API: https://api.destroy.tools/v1/check?domain=solana.traxr.pro Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,767 domains (12,434 alive under monitoring, 157,933 confirmed takedowns/dead). Site: https://phishdestroy.io