# airs-solan.com — MALICIOUS > Avoid airs-solan.com - a phishing site posing as SolDrop to steal credentials. Do not claim the 15 SOL airdrop on this fraudulent domain. ## Summary PhishDestroy identifies airs-solan.com as a generic phishing domain actively targeting users with a fake cryptocurrency airdrop offer. The site masquerades as a SolDrop promotion, enticing victims to claim a supposed 15 SOL airdrop, a tactic commonly used to harvest sensitive information. This domain was registered recently on February 21, 2026, indicating it is part of a fresh phishing campaign likely aiming at crypto enthusiasts. Technical analysis reveals that airs-solan.com resolves to the IP address 104.21.31.75 and currently appears on four distinct security blocklists, reinforcing its malicious classification. VirusTotal reports that 7 out of 95 security vendors flag this domain, reflecting moderate detection coverage. The phishing page's title, "SolDrop - Claim Your 15 SOL Airdrop," is designed to lure unsuspecting users into divulging their credentials or wallet details. The domain remains active, posing an ongoing risk to internet users. PhishDestroy recommends immediate caution and avoidance of airs-solan.com. Users should refrain from interacting with the site or submitting any personal or financial information. Security teams are advised to update their blocklists and monitor for related phishing attempts leveraging similar social engineering lures. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Page title: SolDrop - Claim Your 15 SOL Airdrop ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 104.21.31.75 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - SSL Issuer: WE1 ## Detection Status - VirusTotal: 7 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "CyRadar", "Ermes", "Fortinet", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 4 hits Lists: ["PhishDestroy", "MetaMask", "ScamSniffer", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019bb282-8aab-763d-b3bf-978757df2ed6.png - PhishDestroy: https://phishdestroy.io/domain/airs-solan.com/ - LLM endpoint: https://phishdestroy.io/domain/airs-solan.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/airs-solan.com/ Last updated: 2026-03-19