Analysis of airdrop-ads.xyz indicates an active crypto‑drainer infrastructure that was registered on July 30, 2026 through Chengdu west dimension digital technology Co., LTD. The domain resolves to the Cloudflare‑hosted address 172.67.180.149 and uses the authoritative nameservers dolly.ns.cloudflare.com and melnicoff.ns.cloudflare.com. The site has been listed on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, confirming that threat‑intel communities have observed malicious activity associated with it.
VirusTotal records show that the domain was scanned by 91 antivirus and URL‑reputation vendors, none of which reported a detection at the time of the scan; this absence of detections does not imply safety and must be weighed against the other indicators. Current intelligence flags the domain as high‑risk and still active. No public page title, SSL certificate details, or HTTP response codes have been disclosed, leaving the specific delivery mechanisms of the drainer undefined.
Defenders should immediately add airdrop-ads.xyz and its resolved IP 172.67.180.149 to network‑level deny lists, monitor DNS queries for similar newly‑registered domains from the same registrar, and consider sinkholing the IP range. Continuous re‑scanning with multi‑vendor services is recommended to capture any future payload changes, and security teams should alert end‑users to avoid interactions with unsolicited crypto‑related offers that reference the airdrop‑ads.xyz domain.