solairdrops-2d[.]netlify[.]app
solairdrops-2d.netlify.app was observed on 2026-08-02 as an active crypto‑drainer infrastructure. The domain is hosted on Netlify’s static‑site service, indicated by the “.netlify.app” suffix, and resolves to Netlify’s shared IP ranges. No malicious payload was retrieved, but the domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed.
VirusTotal records show the URL was submitted to 91 scanning engines; none of the engines raised a detection at the time of analysis. While the absence of a detection does not imply safety, it demonstrates that the current signatures do not yet recognize the site’s behavior. The site’s page title, target brand, and content have not been publicly disclosed, so the exact impersonation technique remains unknown.
Investigators have not identified any SSL certificate anomalies; the site presents a valid HTTPS certificate issued to the Netlify domain, which is typical for legitimate Netlify deployments. The lack of observed malicious code means that attribution relies on the blocklist entries and the classification of the domain as a “crypto drainer.” Defenders should continue to deny connections to the domain at the network perimeter, add the host to URL filtering policies, and monitor DNS queries for the “solairdrops-2d.netlify.app” name. Ongoing telemetry collection, including sandbox execution of any downloaded payloads and correlation with known crypto‑drainer indicators, is recommended to confirm the threat’s intent and to update detection rules.
Threat Response Pipeline
Public Blocklist Status
Technologies · 4 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of solairdrops-2d.netlify.app · checked Aug 2, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive