This domain, solairdrops-nm.netlify.app, is currently active and has been classified as a high‑risk crypto drainer. Infrastructure analysis shows the site is hosted on Netlify and resolves to the IPv4 address 63.176.8.218. The domain was scanned by VirusTotal, where 91 antivirus and URL‑reputation engines examined the URL and none reported a detection at the time of analysis; the absence of a flag does not imply safety.
Blocklist monitoring indicates that PhishDestroy, MetaMask, and SEAL have added the domain to their deny lists, and it appears on three additional security blocklists, reinforcing the suspicion of malicious intent. The registrar information confirms Netlify as the service provider, and the nameserver lookup returned no records (NS_NOT_FOUND), which is consistent with Netlify’s dynamic DNS handling. No SSL certificate details, HTTP response codes, or page‑title information are presently available, limiting visibility into the payload delivery mechanism.
The primary uncertainty concerns the exact malicious infrastructure and any associated command‑and‑control endpoints, as no malware family or toolkit has been identified. Defenders should immediately block the domain and the associated IP address at network perimeters, add it to DNS sinkhole or proxy deny lists, and monitor outbound traffic for connections to 63.176.8.218. Continuous re‑scanning with multiple vendors is advised, as the threat landscape may evolve and future analyses could reveal additional indicators.