airdrop[.]moonbirbs[.]network
Evidence Summary
The domain airdrop.moonbirbs.network is confirmed as infrastructure supporting an airdrop scam, a specific threat type involving fraudulent cryptocurrency token distributions. Currently offline, this domain previously impersonated legitimate airdrop campaigns to deceive users into disclosing wallet credentials or transferring funds. Analysis indicates this was an active component of a broader deception operation targeting crypto asset holders. Infrastructure analysis reveals the domain was flagged by 9 of 95 security vendors on VirusTotal, indicating high confidence in its malicious classification. Registered on February 21, 2026, the domain resolved to IP address 188.114.96.3, hosted on Cloudflare infrastructure (AS13335) in the United States. No SSL certificate was present, a common red flag for fraudulent sites. The domain appeared on three security blocklists, including entries from major threat intelligence platforms, further corroborating its malicious intent. Creation metadata and hosting patterns align with known airdrop scam campaigns observed in early 2026. Current status shows the domain as taken offline, though residual risks remain for users who may have interacted with it prior to deactivation. Organizations and individuals are advised to block the domain and associated IP at network perimeters. Security teams should review logs for connections to 188.114.96.3 or the domain name, particularly from crypto-related services. Users who engaged with this domain should assume credential exposure and revoke any wallet authorizations or transactions initiated during the interaction window. Proactive monitoring for similar domains using the 'moonbirbs' naming pattern is recommended to prevent follow-on attacks.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive