# airdrop-pump9.fun — SUSPICIOUS > Caution advised for airdrop-pump9.fun. This domain is under investigation for crypto draining activity; avoid interaction to protect your assets. ## Summary PhishDestroy identifies airdrop-pump9.fun as a suspicious domain potentially involved in crypto drainer operations. Classified under the crypto threat category, this domain aims to exploit users via fraudulent airdrop schemes. Despite lacking detections from major security vendors, its behavior and context raise concerns warranting ongoing analysis. airdrop-pump9.fun was registered through NameSilo, LLC and resolves to IP address 172.67.194.118. The domain creation date is suspiciously set in the future (March 6, 2026), which is an unusual indicator often associated with deceptive registrations or system clock tampering. VirusTotal scans currently show no flags, but the domain infrastructure and naming convention align with common crypto scam tactics. The domain remains active and under investigation by PhishDestroy. Users are strongly advised to avoid engaging with the site or providing any credentials. Continuous monitoring is recommended to detect any emerging malicious patterns or security vendor classifications. Immediate caution is prudent given the potential financial risk posed by crypto drainer scams like this. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 0) - Scam type: Airdrop Scam - Page title: Airdrop - Claim Your Tokens ## Domain Intelligence - Registered: 2026-03-08 13:07:01 - Registrar: NameSilo, LLC - Country: US - IP: 172.67.194.118 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["stevie.ns.cloudflare.com", "cris.ns.cloudflare.com"] - SSL Issuer: none ## Detection Status - VirusTotal: 1 vendors flagged Vendors: ["Kaspersky"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://i.ibb.co/YB5zkhv4/0572a9ba8e41.png - Cloudflare Radar: https://radar.cloudflare.com/scan/bdb802d3-eac1-4573-a697-fddf0f0618a3 - Wayback Machine: https://web.archive.org/web/https://airdrop-pump9.fun - PhishDestroy: https://phishdestroy.io/domain/airdrop-pump9.fun/ - LLM endpoint: https://phishdestroy.io/domain/airdrop-pump9.fun/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/airdrop-pump9.fun/ Last updated: 2026-03-19