# usor.vsolana.com — MALICIOUS — Crypto Drainer (Solana Drainer) > Check usor.vsolana.com, a crypto draining domain linked to Solana Drainer kit. Active and under investigation. Stay safe with PhishDestroy insights. ## Summary PhishDestroy identifies usor.vsolana.com as a crypto drainer threat targeting users through fraudulent tokenization of real-world oil assets on a ledger blockchain platform. Such crypto drainer schemes aim to illicitly extract users’ Solana-based assets, risking significant financial loss. This makes vigilance critical in digital asset interactions. The domain usor.vsolana.com was registered recently on March 4, 2026, via NAMECHEAP INC and resolves to the IP address 63.176.8.218. Despite showing zero detections on VirusTotal among 95 security vendors, the site’s association with a Solana Drainer kit and its crypto-focused infrastructure raise strong concerns. Its active status and novel registration suggest ongoing malicious operations under investigation. Users are advised to exercise caution when interacting with this domain or similar Solana blockchain tokenization platforms. Avoid entering private keys or seed phrases, and refrain from authorizing transactions through unfamiliar third-party sites. Continuous monitoring and using trusted security tools are recommended to protect digital assets against emerging crypto draining threats such as usor.vsolana.com. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: dead (HTTP 0) - Drainer type: Solana Drainer - Target brand: Solana - Page title: U.S Oil ($USO) - Tokenising Real World Oil using Ledger Blockchain ## Domain Intelligence - Registered: 2026-03-04 10:49:17 - Registrar: NameCheap, Inc. - Country: US - IP: 63.176.8.218 - IP Country: DE - IP City: Frankfurt am Main - IP Org: AS16509 Amazon.com, Inc. - Nameservers: dns1.registrar-servers.com dns2.registrar-servers.com - SSL Issuer: none ## Detection Status - VirusTotal: 1 vendors flagged Vendors: ["SOCRadar"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://i.ibb.co/GqGBwB1/ebed15ec8b32.png - Cloudflare Radar: https://radar.cloudflare.com/scan/2e88f63e-76cb-4a8c-8f1c-e83a48fd8571 - PhishDestroy: https://phishdestroy.io/domain/usor.vsolana.com/ - LLM endpoint: https://phishdestroy.io/domain/usor.vsolana.com/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/usor.vsolana.com/ Last updated: 2026-03-19