VirusTotal
14 / 95
“FLARE token Airdrops on TRUSTPAD-ETHER for XRP Holders, The Exclusive Multi-Chain Airdrops”
This domain, flair-live.online, was observed hosting a fake airdrop campaign that impersonates the Across brand. The site is currently offline, and its hosting infrastructure points to the IP address 102.209.117.148, which belongs to AS329184 Host Africa (Pty) Ltd in South Africa. The domain was registered on October 28, 2025 through Cosmotown Inc and uses the name servers ns1.host-ww.net, ns2.host-ww.net, ns3.host-ww.net, and ns4.host-ww.net. No TLS certificate is presented, leaving the HTTP connection unencrypted. The page title retrieved from the site reads "FLARE token Airdrops on TRUSTPAD-ETHER for XRP Holders, The Exclusive Multi-Chain Airdrops", matching the typical wording of the Airdrop Scam kit identified in multiple investigations.
Analysis of threat‑intelligence feeds shows the domain appears in two AlienVault OTX pulses and is listed on five external blocklists. Commercial detection services have flagged the domain, with 14 of 95 VirusTotal scanners returning a positive result. The infrastructure has been actively blocked by PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. The campaign leverages the Airdrop Scam kit to lure cryptocurrency holders, specifically targeting users of the Across platform.
While the current HTTP status indicates the site is taken offline, the underlying IP and name server configuration remain active and may be reused for future campaigns. Defenders are advised to add flair‑live.online and its resolving IP to blocklists, monitor the associated name servers for new domain registrations, and ensure that any inbound traffic to the identified IP is denied at the perimeter. Continuous observation of OTX pulse updates and VirusTotal re‑scans is recommended to detect potential re‑activation. Organizations handling Across‑related user credentials should reinforce user education about unsolicited airdrop offers and employ strict email filtering to reduce exposure to similar social‑engineering vectors.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x445cC9518cF7bc7386A2e3aaF510650b0FB05f5FFormat validated · Domain analysisIoC extraction recorded 2026-08-02 04:28:46 UTC
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='flair-live.online', port=80): Max retries exceeded with url: / (Caused by NewConnectionErr
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
ns1.host-ww.netns2.host-ww.netns3.host-ww.netns4.host-ww.netLocation describes the IP network.
13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Reported by 1 community member, first seen Nov 7, 2025
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive