# PhishDestroy threat dossier — web3airdrop.live ================================================================ Fetched: 2026-05-08 21:55:29 UTC Canonical: https://phishdestroy.io/domain/web3airdrop.live/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 79/100 (PhishDestroy scoring — see methodology below) Targeted brand: Airdrop Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 11/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Lionic, Sophos, Webroot Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.198.79.1 Page title: Web3Airdrop | Multi-Chain On-Chain Analytics HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: REPORTS FILED AND IGNORED — registrar did not act on these notifications. Domain still online. Reports filed: 1 independent abuse notifications First report: 2026-05-08 22:51:43 UTC Days since first notice: 1 — no registrar action, domain remains online ICANN Compliance CC'd on at least one escalation — non-response is on record. Methodology: follow-up reports are sent ONLY when a victim re-submitted a re-report via our public form, our monitoring detected the domain resurfacing in SEO/feeds, OR our live-checker confirmed the domain is still technically active and fraudulent. Each report contains: VT verdict, URLScan snapshot, WHOIS, SSL metadata, IP/hosting chain, impersonated-brand evidence, drainer/kit classification, screenshots, and a cryptographic hash of the forensic PDF. ICANN RAA Sec. 3.18 applies. Per-report timeline: https://phishdestroy.io/domain/web3airdrop.live/#coordinated-suppression ## TIMELINE ---------------------------------------------------------------- First detected: 2026-05-08 22:51:41 UTC (by PhishDestroy tracker) First reported: 2026-05-08 19:51:43 UTC (abuse notice filed) Last verified: 2026-05-08 23:47:08 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e0924-ffc6-72ee-87c5-264fad777372/ Wayback Machine: https://web.archive.org/web/*/web3airdrop.live crt.sh CT logs: https://crt.sh/?q=%25.web3airdrop.live Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=web3airdrop.live AlienVault OTX: https://otx.alienvault.com/indicator/domain/web3airdrop.live URLhaus: https://urlhaus.abuse.ch/host/web3airdrop.live/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-08 22:52:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies web3airdrop.live as an active brand impersonation phishing domain targeting cryptocurrency airdrop scams. This domain is engineered to deceive users by mimicking legitimate airdrop promotions, specifically exploiting the trust associated with cryptocurrency giveaways. This domain presents an elevated risk level due to its active impersonation of Airdrop Scam, a known cryptocurrency airdrop platform. Intelligence indicates it has been flagged by 11 out of 95 security vendors on VirusTotal, blocked by MetaMask and SEAL, and listed on two security blocklists. The domain uses a Let's Encrypt SSL certificate, suggesting an attempt to appear legitimate. Further technical indicators include an unknown creation date, but current status as active, and the domain is hosted with no additional IP intelligence provided. The low trust score is evidenced by the VirusTotal detection ratio and blocklist presence, reinforcing its malicious intent. Mitigation for this brand impersonation phishing threat requires immediate avoidance of the domain and any associated links or prompts claiming to offer airdrops. Users should verify any airdrop offers through official channels and use browser extensions or security tools that block known malicious domains. Additionally, cryptocurrency users should enable transaction simulation tools like MetaMask's blockaid to prevent unauthorized transfers. Organizations should consider adding this domain to internal blocklists and threat intelligence feeds to protect users and systems. Immediate reporting to security teams or platforms like SEAL is recommended to aid in takedown efforts and prevent further victimization. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-1778269896-web3airdrop.liv Favicon MD5: 5f5ace0b35cc0eff3ec3fcc465671a83 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/web3airdrop.live/ JSON API: https://api.destroy.tools/v1/check?domain=web3airdrop.live Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 147,363 domains (48,468 alive under monitoring, 98,477 confirmed takedowns/dead). Site: https://phishdestroy.io