Analysis indicates that solanaswap.pro was registered on July 02, 2026 and is currently active. The domain is delegated to the Anycast DNS servers ns1.anycastdns.cz and ns2.anycastdns.cz, and resolves to the IPv4 address 186.2.175.35. It appears on a single security blocklist and is listed as blocked by PhishDestroy. The registrar entry shows registration through Fewmoretaps OU operating under the Trade Name Trustname.com.
The site is associated with the Solana Drainer kit, a known crypto‑drainer module used to illicitly transfer assets from wallets on the Solana blockchain. VirusTotal records indicate that the domain was submitted to 91 scanning engines; none of the engines flagged the host at the time of analysis, which does not constitute a safety assurance. No additional public intelligence such as Safe Browsing alerts, OTX mentions, SSL certificate details, or HTTP response codes is available in the current dataset. The observable infrastructure—recent registration, use of generic Anycast name servers, and a single blocklist appearance—suggests a fast‑flux style deployment aimed at evading rapid takedown.
The presence of the Solana Drainer kit aligns the threat with credential‑stealing or wallet‑draining campaigns targeting cryptocurrency users. Defenders should add the IP address 186.2.175.35 and the domain solanaswap.pro to inbound and outbound filtering rules, monitor DNS queries for the associated name servers, and share indicator data with upstream protection services. Continuous re‑scanning with multi‑engine services is advised, as future analyses may reveal malicious payloads or additional detections. Network teams are encouraged to block any traffic to the domain and to investigate any internal Solana wallet activity that may have interacted with the address.