# solsfaucet.live — SUSPICIOUS > Critical alert: solsfaucet.live impersonates a crypto faucet in an active phishing campaign. Only 0 detections on VirusTotal. Check the full report. ## Summary solsfarcet.live has been identified as a malicious domain actively hosting a generic cryptocurrency faucet scam. This fraudulent website mimics the functionality of legitimate crypto faucets—websites that dispense small amounts of cryptocurrency to users for completing simple tasks—with the sole intent of stealing deposited funds and harvesting user credentials. The domain leverages social engineering tactics, likely propagated through social media, forums, or messaging platforms, to lure victims into connecting their digital wallets under the pretext of earning rewards. Threat intelligence indicates the use of a drainer script embedded within the site, designed to siphon digital assets once wallet connectivity is established. The domain does not appear to impersonate a specific brand but instead positions itself as an independent, high-reward opportunity, which is characteristic of opportunistic scam campaigns targeting crypto enthusiasts. The domain solsfarcet.live resolves to the IP address 104.21.6.142 and is registered through NameCheap, Inc., with a creation date of January 22, 2026. VirusTotal currently reports a detection score of 0/95, indicating no antivirus engines have flagged the domain or its associated infrastructure at this time. Despite this, the domain holds a valid SSL certificate issued by Google Trust Services (GTS), which may help it evade initial suspicion by appearing legitimate to users. The domain remains unlisted on major blocklists as of this analysis, suggesting it is a recently deployed threat with limited historical exposure. Notably, the domain’s recent registration date and zero detections underscore the importance of proactive monitoring, as such threats often gain traction quickly before broader detection mechanisms are updated. As of the latest assessment, solsfarcet.live remains active and is classified with a status of under_investigation, with an overall risk level still being evaluated. The absence of detections and historical intelligence highlights a window of opportunity for defensive action—organizations and users are strongly advised to block both the domain and its associated IP address at the network perimeter to prevent access. Immediate response actions include updating DNS sinkholes, adjusting firewall rules, and distributing threat intelligence to relevant stakeholders. While the current risk is assessed as under_investigation, the potential for rapid escalation exists given the domain’s recent activation and lack of exposure. Users are cautioned against engaging with any unsolicited links or advertisements promoting crypto faucets, and should verify the legitimacy of such services through official channels before interacting with them or connecting wallets. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-01-22 22:02:28 - Registrar: NameCheap, Inc. - IP: 104.21.6.142 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/3ee3de27-9f8f-45bd-afa7-f54c77696f26 - PhishDestroy: https://phishdestroy.io/domain/solsfaucet.live/ - LLM endpoint: https://phishdestroy.io/domain/solsfaucet.live/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/solsfaucet.live/ Last updated: 2026-03-24