# www.hehonsolana.fun — MALICIOUS — Crypto Drainer (Solana Drainer) > Alert: www.hehonsolana.fun is linked to a Solana crypto drainer kit. Currently under investigation. Avoid interacting with this suspicious domain. ## Summary PhishDestroy identifies www.hehonsolana.fun as a domain associated with a Solana crypto drainer threat, a malicious tool designed to illicitly extract cryptocurrencies from victims' wallets. Although the domain is not currently flagged by any major security vendors, its recent creation and the deployment of a known drainer kit make it a serious concern for crypto users. The unique seed d33ec5 highlights the evolving tactics used by threat actors targeting Solana blockchain users. The infrastructure analysis shows that www.hehonsolana.fun was registered on March 2, 2026, through HOSTINGER operations, UAB, and resolves to IP address 103.169.142.0. Despite no detections on VirusTotal, the domain ties to a Solana Drainer kit suggest malicious intent. The domain’s minimal page content titled simply “heh” also aligns with typical phishing or drain kit landing pages meant to deceive users. This domain remains active and is currently under further investigation to gather additional intelligence. Users are strongly advised to refrain from visiting www.hehonsolana.fun or submitting any sensitive information on this site. Those involved in the Solana ecosystem should exercise caution by using official and verified platforms only. Maintaining updated wallet security practices and monitoring wallet activity for unauthorized transactions are critical steps to mitigate risks. PhishDestroy will continue to monitor this domain and update threat intelligence accordingly. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: dead (HTTP 0) - Drainer type: Solana Drainer - Target brand: Solana - Page title: heh ## Domain Intelligence - Registered: 2026-03-09 15:07:01 - Registrar: HOSTINGER operations, UAB - Country: LT - IP: 103.169.142.0 - IP Country: AU - IP City: Sydney - IP Org: AS209242 Cloudflare London, LLC - Nameservers: ns1.dns-parking.com ns2.dns-parking.com - SSL Issuer: none ## Detection Status - VirusTotal: 0 vendors flagged Vendors: [] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://i.ibb.co/GQ2XSpfY/88e660e19cb0.png - Cloudflare Radar: https://radar.cloudflare.com/scan/f09e2969-0057-499f-b606-a8e25c8db488 - PhishDestroy: https://phishdestroy.io/domain/www.hehonsolana.fun/ - LLM endpoint: https://phishdestroy.io/domain/www.hehonsolana.fun/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/www.hehonsolana.fun/ Last updated: 2026-03-19