Analysis of the domain web3-ai08.top shows that it was registered through Dynadot LLC on July 30, 2026 and is currently active. The authoritative nameservers listed are ns1.dyna-ns.net and ns2.dyna-ns.net, and DNS resolution points to the IPv4 address 85.137.57.218. The domain has been added to three security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, indicating that at least three independent threat‑sharing communities consider it malicious.
VirusTotal reports that the domain was scanned by 91 antivirus and URL‑reputation vendors; none of the vendors have flagged it at the time of the scan, but the absence of detections does not constitute a safety guarantee. No publicly available page title, SSL certificate details, HTTP response codes, or content snapshots have been disclosed, so the exact landing page and any credential‑harvesting mechanisms remain unverified. The lack of brand‑specific references means the impersonated target cannot be confirmed, and the site appears to be a generic credential‑collection operation.
Defenders should incorporate the domain and its resolving IP address into URL filtering and DNS‑blocking policies, monitor for any future reputation changes on VirusTotal or related services, and treat any user‑initiated connections to the host as potentially hostile. Continuous telemetry collection on traffic to 85.137.57.218 and periodic re‑scanning of the domain are recommended to detect any evolution of the payload or the introduction of malicious binaries.