On 31 July 2026, the domain solairdrops-gp.netlify.app was observed as part of an active crypto‑drainer campaign. The site is hosted on Netlify and resolves to the IPv4 address 63.176.8.218. The domain has been listed on a single public blocklist and was previously blocked by the PhishDestroy feed. Name server lookup returned no records, indicating either a misconfiguration or deliberate concealment of the authoritative servers.
VirusTotal has recorded 91 vendor scans for this host; none of the scanners raised a detection at the time of analysis, which does not constitute assurance of benign behavior. No additional intelligence such as Safe Browsing verdicts, OTX sightings, SSL certificate details, HTTP response codes, or trust‑score metrics are currently available. The lack of a page title or other content metadata means the exact payload delivered by the site cannot be confirmed, but the designation as a crypto drainer suggests it likely attempts to exfiltrate cryptocurrency wallets or private keys. Defenders should add solairdrops‑gp.netlify.app to domain‑based deny lists, block outbound connections to its resolved IP 63.176.8.218, and monitor DNS queries for similar Netlify‑hosted subdomains.
Continuous re‑scanning with multi‑vendor services is advised, as new detections may emerge. Correlation with other Netlify‑origin threats may help surface related infrastructure, so analysts should query threat‑intel platforms for additional indicators sharing the same hosting provider or IP range. Until further evidence is gathered, the domain remains under investigation and should be treated as high‑risk for any organization handling cryptocurrency assets.