The domain web3-ai05.top, registered through Dynadot LLC on July 30, 2026, is assessed as high risk due to its association with an active phishing campaign. Infrastructure analysis shows that the domain resolves to IP address 85.137.57.218 and utilizes nameservers ns1.dyna-ns.net and ns2.dyna-ns.net. At the time of reporting (August 01, 2026), the domain remains operational. While a recent scan by 91 security vendors shows no current detections, this absence is not an assurance of legitimacy, especially in the context of early-stage or newly launched phishing domains where detection coverage may lag.
Further reinforcing the threat assessment, web3-ai05.top appears on three independent security blocklists and is actively blocked by prominent security vendors PhishDestroy, MetaMask, and SEAL. This aggregation of blocklist data provides clear external validation of the domain's malicious status, despite the lack of real-time engine detections. No evidence is present in the provided intelligence regarding the specific phishing scheme employed or targeted brands, and the actual site content has not been analyzed. Thus, the precise lure or attack vector remains undetermined at this stage.
Given the recent domain registration, active status, and corroborated blocklist presence, defenders should treat web3-ai05.top as a confirmed phishing threat. It is recommended to implement network blocks and update endpoint security controls accordingly. Ongoing monitoring for related infrastructure or additional indicators of compromise is advised, as phishing campaigns frequently expand or modify assets to evade detection.