Analysis of claim.liveart-airdrop.xyz shows a newly registered domain created on July 28, 2026 and managed through NameSilo, LLC. The domain uses Cloudflare authoritative nameservers (agustin.ns.cloudflare.com and nola.ns.cloudflare.com), indicating that traffic is routed via Cloudflare’s edge network. DNS resolution points to IP address 188.114.97.3, an address belonging to Cloudflare’s global CDN infrastructure, which masks the underlying hosting provider and complicates direct attribution. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy intelligence feed, suggesting that it has already been identified as malicious by at least one reputable source.
VirusTotal records show that the domain was scanned by 91 anti‑malware engines; none of those engines raised a detection at the time of scanning. While the absence of detections does not constitute a safety guarantee, it demonstrates that the domain has not yet been flagged by automated scanners, reinforcing the need for proactive defensive measures. No public Safe Browsing, OTX, SSL certificate, HTTP status, trust‑score, page‑title, or evidence‑link data were supplied, leaving those vectors unverified.
Consequently, the observable evidence consists primarily of registration details, DNS configuration, IP association, blocklist presence, and the VirusTotal scan count. Defenders should prioritize blocking the domain at DNS and proxy layers, incorporate it into internal blocklists, and monitor for any outbound connections to the resolved IP. Continuous re‑scanning with multiple vendors and periodic threat‑intel checks are advised to capture any future changes in the domain’s behavior or reputation.