Analysis indicates that the domain solairdrops-jf.netlify.app is currently active and hosted on Netlify infrastructure. The domain resolves to the IP address 35.157.26.135, which belongs to the Netlify hosting pool. The registrar information shows the site was provisioned through Netlify, and the authoritative nameserver data is unavailable (NS_NOT_FOUND). A VirusTotal scan involving 91 vendor engines returned no detections, but the lack of a match does not constitute evidence of benign behavior. The domain is listed on a single external blocklist and is actively blocked by the PhishDestroy service, suggesting that at least one security community has observed malicious activity associated with it.
The threat classification supplied is a crypto drainer, indicating that the site likely attempts to illicitly divert cryptocurrency assets from victims. The risk level is marked as under investigation, and the status remains active, implying that the campaign may still be operational. Uncertainty remains regarding the specific tactics, techniques, and procedures employed by the actor, as no page‑title, SSL certificate details, or HTTP response codes have been disclosed. Likewise, no attribution to an ASN, country, or known malware kit is available.
Defenders should therefore treat the domain as suspicious and implement preventive controls. Recommended actions include adding the IP address 35.157.26.135 to outbound block lists, configuring web‑gateway filters to deny traffic to the domain, and monitoring DNS logs for queries to solairdrops-jf.netlify.app. Continuous re‑evaluation of VirusTotal and other threat‑intel feeds is advised, as additional detections may appear over time. Incident response teams should also consider isolating any endpoints that have communicated with the domain and reviewing cryptocurrency wallet activity for unauthorized transfers.