rexas-drop[.]online
“Deployment Unavailable”
Evidence Summary
The domain rexas-drop.online is associated with generic phishing activities posing an elevated risk. The site is currently taken offline and does not appear to impersonate any known brand or utilize any specific draining kit. Questions of safety regarding rexas-drop.online would lead to the conclusion that it is indeed a phishing site and not safe for users.
Technical indicators include 2 of 95 VirusTotal vendors flagging the domain, with detections by CRDF and Gridinsoft. The registrar is NameSilo, LLC, and it was created on July 07, 2025. The domain resolves to the IP address 76.76.21.22, which is located in the US under AS16509 Amazon.com, Inc. Additionally, rexas-drop.online appears on 1 security blocklist (PhishDestroy) and uses an SSL certificate issued by R11.
For individuals who may have interacted with rexas-drop.online, it is crucial to take immediate safety steps. If there was potential credential phishing, it is advisable to change passwords and enable two-factor authentication on affected accounts. For those who transacted or shared wallet information, revoking token approvals and moving funds to a new wallet is recommended. Users can report phishing attempts to the appropriate authorities or security organizations.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive