Analysis of the domain web3-ai06.top indicates it is currently active and classified as a high‑risk generic phishing operation. The domain was registered on July 30, 2026 through Dynadot LLC and uses the authoritative name servers ns1.dyna-ns.net and ns2.dyna-ns.net. DNS resolution points to the IPv4 address 85.137.57.218, which is still reachable as of the report date.
The domain appears on three external security blocklists and has been explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services, reinforcing the assessment of malicious intent. VirusTotal has recorded scans from 91 antivirus vendors, none of which have raised a detection at the time of analysis; this absence of detections should not be interpreted as an indication of safety. No information is available regarding SSL/TLS configuration, HTTP response codes, page title, or any visual content, leaving the exact phishing payload and target brand unspecified.
Defenders should prioritize immediate containment measures: add web3-ai06.top and its resolving IP 85.137.57.218 to network‑level deny lists, enforce URL filtering rules consistent with the blocklist entries, and monitor for any outbound connections to the host. Continuous re‑evaluation is advised, as future scans may reveal additional indicators or payload changes. The combination of recent registration, active DNS resolution, multiple blocklist listings, and targeted blocking by well‑known anti‑phishing tools underscores the necessity for proactive defensive actions.