soldrop[.]solvault[.]ws
“Solana”
soldrop.solvault.ws — Conteúdo indisponível (HTTP 502). Representação da marca: Solana; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 4/93 (ADMINUSLabs, ArcSight Threat Intelligence, Fortinet, SOCRadar); PhishDestroy score 65/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On July 25, 2026, the domain soldrop.solvault.ws was observed in an elevated‑risk brand‑impersonation campaign targeting the Solana ecosystem. The domain was registered on 21 February 2026 and is currently taken offline. DNS resolution points to the IPv6 address 2606:4700:3032::6815:4209, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. VirusTotal analysis shows that four of ninety‑three security vendors flagged the domain, indicating partial detection across the vendor ecosystem.
The site is listed on a single security blocklist and has been actively blocked by the PhishDestroy filtering service. The TLS certificate presented by the site is identified as “WE1”, which does not correspond to a recognized certificate authority and is typical of quickly‑issued certificates used by malicious actors. The HTTP response returned a page title of “Solana”, confirming that the adversary intended to impersonate the Solana brand, consistent with the classification of a crypto‑scam campaign. No additional content or page‑behavior details have been published, leaving the exact phishing vector (e.g., credential harvesting, wallet address substitution) unverified.
Defenders should prioritize adding the domain to URL filtering and DNS blocklists, enforce TLS inspection to detect the WE1 certificate, and monitor Cloudflare‑associated address space for similar impersonation attempts. Continuous re‑scanning with multi‑vendor platforms is recommended to capture any future changes in detection status. Organizations handling Solana‑related assets should educate users about unsolicited links referencing soldrop.solvault.ws and consider implementing domain‑based allow‑lists that exclude untrusted subdomains.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
“I clicked on an Airdrop announcement from the "Solana Community" on a Twitter account that was 16 years old. To qualify for the drop (0.5 - 1 SOL) I needed to have a min. of $175 in SOL. I had $177 in SOL so I connected my wallet and it transferred the exact $175 out to their wallet instead.”
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo