# airdrop.lineas.run — MALICIOUS > Warning: airdrop.lineas.run is an active crypto drainer domain. Avoid interactions to protect your assets and personal data from theft. ## Summary PhishDestroy identifies airdrop.lineas.run as a medium-risk crypto drainer domain actively targeting users. It employs deceptive tactics under the guise of an airdrop page titled “Nur einen Moment…”. The domain was registered recently on February 21, 2026, and resolves to the IP 104.21.32.1. It is currently listed on three security blocklists and flagged by 5 out of 95 VirusTotal antivirus engines, indicating moderate detection confidence. Users are advised to avoid this domain and any related links. Security teams should monitor its activity due to its ongoing status. Blocking and reporting this domain can help mitigate potential asset theft risks associated with crypto draining threats. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Scam type: Airdrop Scam - Page title: Nur einen Moment… ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 104.21.32.1 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - SSL Issuer: WE1 ## Detection Status - VirusTotal: 5 vendors flagged Vendors: ["ChainPatrol", "alphaMountain.ai", "CyRadar", "Fortinet", "Gridinsoft"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/01991af2-ec62-712d-bc0c-c8a8580b27aa.png - PhishDestroy: https://phishdestroy.io/domain/airdrop.lineas.run/ - LLM endpoint: https://phishdestroy.io/domain/airdrop.lineas.run/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/airdrop.lineas.run/ Last updated: 2026-03-19