# airdrop.magicknewton.world — MALICIOUS > Explore details on airdrop.magicknewton.world, a medium-risk crypto drainer domain now offline and flagged by multiple security sources. ## Summary PhishDestroy identifies airdrop.magicknewton.world as a medium-risk crypto drainer domain designed to steal cryptocurrency assets from unsuspecting users. The domain was associated with fraudulent airdrop schemes targeting wallet credentials. The domain was registered on February 21, 2026, but currently is classified as a dead domain with infrastructure taken offline. It appeared on two security blocklists and was flagged by multiple VirusTotal vendors, indicating active monitoring by security services. As the domain is offline, immediate risk is reduced; however, users are advised to remain cautious of similar airdrop-themed scams. Continued vigilance and use of security tools like PhishDestroy are recommended to detect emerging threats. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Scam type: Airdrop Scam - Page title: 403 Forbidden ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: Dead domain - IP: 172.67.210.107 - SSL Issuer: WE1 ## Detection Status - VirusTotal: 5 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "CyRadar", "Forcepoint ThreatSeeker", "Fortinet"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "ScamSniffer"] ## Evidence - Screenshot: https://urlscan.io/screenshots/01988181-2b1d-74cc-a9be-f67520109b49.png - PhishDestroy: https://phishdestroy.io/domain/airdrop.magicknewton.world/ - LLM endpoint: https://phishdestroy.io/domain/airdrop.magicknewton.world/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/airdrop.magicknewton.world/ Last updated: 2026-03-17