Analysis of the domain web3-ai09.top as of August 01, 2026 indicates that the site is actively hosted and associated with a high‑risk generic phishing campaign. The domain was registered on July 30, 2026 through Dynadot LLC, a registrar that frequently appears in malicious infrastructure. DNS resolution points to the IPv4 address 85.137.57.218, and the authoritative nameservers are ns1.dyna-ns.net and ns2.dyna-ns.net, both belonging to the same provider.
The domain is currently listed on three public blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple defensive services have observed malicious activity linked to this host. A VirusTotal scan performed by 91 antivirus and URL‑reputation engines returned no detections; however, the absence of a detection does not imply benign behavior and should be interpreted alongside the blocklist evidence. No SSL certificate details, HTTP response codes, or page‑title information are presently available, leaving the content of the site unverified.
The lack of additional telemetry such as OTX tags or Safe Browsing entries further limits situational awareness. Defenders should continue to block traffic to 85.137.57.218 and to web3-ai09.top at the network perimeter, monitor for any connections to the associated nameservers, and consider adding the domain to internal deny lists. Continuous re‑evaluation is advised, as threat actors may modify the payload or infrastructure while the domain remains active.