# airdrops-nexira.live — SUSPICIOUS > Explore findings on airdrops-nexira.live, a suspicious crypto drainer domain currently under investigation for active threats. ## Summary PhishDestroy identifies airdrops-nexira.live as a potentially malicious domain involved in crypto drainer schemes, which pose significant risks by stealthily stealing cryptocurrency assets from unsuspecting users. The threat remains under investigation, highlighting the growing concern over emerging crypto-related scams that leverage deceptive web pages to compromise wallets. airdrops-nexira.live resolves to the IP address 172.67.180.80 and currently registers no detections across multiple security vendors, including VirusTotal, indicating it operates under the radar. The page title "Just a moment..." suggests possible use of redirection or obfuscation tactics to evade detection. While the domain is active, its infrastructure and exact attack vectors require further analysis to confirm its modus operandi. Users are advised to exercise extreme caution when interacting with domains offering unsolicited crypto airdrops or wallet integrations, especially those like airdrops-nexira.live flagged for suspicious activity. Avoid providing private keys or sensitive information, and verify communications through trusted sources. Regular wallet security hygiene and updated anti-phishing tools remain essential defenses against such evolving crypto threats. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Scam type: Airdrop Scam - Page title: Just a moment... ## Domain Intelligence - Registered: 2026-03-09 13:07:02 - IP: 172.67.180.80 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: bristol.ns.cloudflare.com karl.ns.cloudflare.com - SSL Issuer: Let's Encrypt / E7 ## Detection Status - VirusTotal: 2 vendors flagged Vendors: ["Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cd29c-6e36-769d-bf06-f127f4fe6922.png - Cloudflare Radar: https://radar.cloudflare.com/scan/044d9f1f-48d9-4442-8259-56f53a6969ef - PhishDestroy: https://phishdestroy.io/domain/airdrops-nexira.live/ - LLM endpoint: https://phishdestroy.io/domain/airdrops-nexira.live/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/airdrops-nexira.live/ Last updated: 2026-03-19