# x-airdrop.icu — MALICIOUS > Discover the risks behind x-airdrop.icu, a high-risk crypto drainer domain now offline. Learn what made it a threat and current status. ## Summary PhishDestroy identifies x-airdrop.icu as a high-risk crypto drainer domain involved in illicit activity targeting cryptocurrency users. The domain was registered on February 21, 2026, and classified as a crypto theft threat. Technical analysis shows x-airdrop.icu was flagged by 10 out of 95 security vendors on VirusTotal and appeared on one security blocklist. The domain was registered through a dead domain registrar, indicating suspicious infrastructure likely used to evade detection. Currently, x-airdrop.icu is taken offline, reducing risk of further attacks. Users are advised to remain cautious with similar domains and rely on updated threat intelligence to avoid crypto-related scams. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Scam type: Airdrop Scam - Page title: Welcome ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 2606:4700:3034::6815:2dda - SSL Issuer: GTS CA 1P5 ## Detection Status - VirusTotal: 10 vendors flagged Vendors: ["alphaMountain.ai", "BitDefender", "CRDF", "CyRadar", "Forcepoint ThreatSeeker", "G-Data", "Lionic", "SOCRadar", "Sophos", "Webroot"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/d736bc9d-6fae-468a-a180-6db6782e175c.png - PhishDestroy: https://phishdestroy.io/domain/x-airdrop.icu/ - LLM endpoint: https://phishdestroy.io/domain/x-airdrop.icu/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/x-airdrop.icu/ Last updated: 2026-03-19