asteralrdrop[.]xyz
asteralrdrop.xyz — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Revolut; घोटाले का प्रकार: Fake Airdrop. साक्ष्य सारांश: VirusTotal 3/94 (Forcepoint ThreatSeeker, Fortinet, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. रजिस्ट्रार: Ultahost.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
PhishDestroy identifies asteralrdrop.xyz as an active crypto drainer phishing domain currently engaged in fraudulent cryptocurrency withdrawal schemes. The domain operates under an elevated threat classification due to its confirmed malicious infrastructure designed to siphon digital assets from unsuspecting victims. As of the latest intelligence cycle, this domain remains in active status and poses immediate risk to users interacting with cryptocurrency platforms or transaction interfaces.
This domain was flagged by 3 of 95 VirusTotal security vendors, indicating limited but concerning detection coverage despite its malicious intent. Registered through Ultahost, Inc., asteralrdrop.xyz resolves to IP address 104.21.90.201, a known hosting infrastructure frequently associated with fraudulent activities. While the exact registration date is not provided in the current dataset, the domain’s presence on limited blocklists and low trust scores across multiple threat intelligence platforms underscores its elevated risk profile. The combination of low VirusTotal detection, suspicious hosting, and active operational status suggests a sophisticated and evolving threat actor leveraging this domain for crypto theft operations.
Given the confirmed crypto drainer functionality and active status of asteralrdrop.xyz, immediate remediation is required to prevent financial losses. Organizations and individuals are strongly advised to block this domain at the network and DNS levels, flag all associated IP addresses, and update endpoint protection rules to detect and quarantine any inbound or outbound connections. Users should verify cryptocurrency transaction URLs through official channels and avoid interacting with unsolicited airdrop or reward links. Continuous monitoring of this domain and its infrastructure is recommended due to the likelihood of rapid infrastructure changes by the threat actor. Blocklisting via DNS filtering services and integration into threat intelligence feeds is essential to mitigate ongoing exposure.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of asteralrdrop.xyz · checked Mar 26, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260325-5C8EAB Recipient: u-abuse@ultahost.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।