# catwifmask-sol.com — SUSPICIOUS > Investigate catwifmask-sol.com, a low-risk phishing domain linked to $MASK airdrop scams. Learn about its status, risks, and mitigation. ## Summary PhishDestroy identifies catwifmask-sol.com as a low-risk generic phishing domain. The campaign behind this domain specifically targeted users with a deceptive $MASK Airdrop page, aiming to trick victims into providing sensitive information. This domain was registered on February 21, 2026, via MAT BAO CORPORATION and resolved to IP address 188.114.96.3. Although VirusTotal flagged the domain by 2 out of 95 security vendors, it appeared on three security blocklists, indicating some community recognition of its malicious use. The domain’s infrastructure and limited detection suggest a relatively low threat level but warrant cautious handling. Currently, catwifmask-sol.com is offline, reducing immediate risks. Users are advised to avoid interaction with similar airdrop offers and verify domain legitimacy before engagement. Monitoring and blocking this domain should continue to minimize exposure to phishing attempts associated with this campaign. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: $MASK Airdrop ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: MAT BAO CORPORATION - Country: VN - IP: 188.114.96.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["roan.ns.cloudflare.com", "ullis.ns.cloudflare.com"] - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 2 vendors flagged Vendors: ["Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "ScamSniffer"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019af9c4-c555-710e-9bb1-1a24805a6a78.png - Cloudflare Radar: https://radar.cloudflare.com/scan/597d7f9c-2d3a-47e6-97f6-6af2751c5f6a - PhishDestroy: https://phishdestroy.io/domain/catwifmask-sol.com/ - LLM endpoint: https://phishdestroy.io/domain/catwifmask-sol.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/catwifmask-sol.com/ Last updated: 2026-03-19