solairdrops-xq.netlify.app is currently flagged as an active crypto‑drainer site. The domain resolves to the Netlify‑hosted IP address 18.208.88.157 and uses Netlify’s default registration infrastructure; the nameserver query returns NS_NOT_FOUND, indicating that the domain relies on Netlify’s internal DNS. The site has been listed on three independent security blocklists and is actively blocked by PhishDestroy, MetaMask, and the SEAL anti‑phishing consortium. These detections collectively label the domain as a crypto‑drainer, a class of scam that attempts to steal cryptocurrency assets by presenting counterfeit wallet interfaces or transaction prompts.
Public intelligence does not include a page title, SSL certificate details, or HTTP response codes, so the exact content served by the host remains unverified. Similarly, no information on the underlying kit, affiliate campaigns, or geographic hosting beyond the IP address is available. The absence of a disclosed brand target means analysts cannot confirm whether the site is spoofing a specific wallet provider or exchange. Given the confirmed presence on multiple blocklists and the active blocking by major wallet extensions, defensive operators should continue to deny connections to the domain at the network perimeter and enforce browser‑level blocking for any user agents that attempt to resolve it.
Endpoint security solutions should add the IP 18.208.88.157 to deny‑list configurations, and organizations using MetaMask or similar extensions should ensure that the built‑in anti‑phishing features remain enabled. Continuous monitoring of Netlify‑hosted domains for similar IP patterns is recommended, as the provider’s shared hosting model can enable rapid deployment of new malicious sites. Until a definitive content analysis is performed, the domain should be treated as high‑risk and isolated from any credential‑ or key‑handling workflows.