# claim-moonbirds.live — MALICIOUS > claim-moonbirds.live is linked to crypto drainer threats. Stay cautious and avoid interacting with this domain to protect your digital assets. ## Summary PhishDestroy identifies claim-moonbirds.live as an active medium-risk crypto drainer domain. This threat targets cryptocurrency users by attempting to illicitly drain digital wallets. The domain is currently active and resolves to IP 104.21.40.219. It appears on two security blocklists, and three security vendors on VirusTotal flag it, supporting its malicious intent. The unique seed 9a5da7 helped uncover its suspicious footprint. Users should avoid any engagement with claim-moonbirds.live and ensure their crypto wallets remain offline or secured. PhishDestroy continues to monitor the domain's status and alerts users to maintain vigilance against such ongoing threats. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 200) - Page title: Birb TGE ## Domain Intelligence - Registered: 2026-03-04 17:07:02 - Registrar: REGISTRAR_NOT_FOUND - IP: 104.21.40.219 - Nameservers: pranab.ns.cloudflare.com tegan.ns.cloudflare.com ## Detection Status - VirusTotal: 14 vendors flagged Vendors: ["BitDefender", "CRDF", "ChainPatrol", "CyRadar", "Fortinet", "G-Data", "Google Safebrowsing", "Gridinsoft", "Lionic", "SOCRadar", "Seclookup", "Sophos", "Trustwave", "alphaMountain.ai"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://i.ibb.co/tMcQrfLx/70ce96667d2e.png - Cloudflare Radar: https://radar.cloudflare.com/scan/716bd7dd-3889-46e1-bcb8-02ba399e9e30 - PhishDestroy: https://phishdestroy.io/domain/claim-moonbirds.live/ ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/claim-moonbirds.live/ Last updated: 2026-03-14