solairdrops-tl.netlify.app was observed on a single security blocklist and is actively blocked by the PhishDestroy feed. The domain is hosted on Netlify and resolves to the IPv4 address 63.176.8.218; no authoritative nameserver information could be retrieved (NS_NOT_FOUND). VirusTotal records indicate the domain has been scanned by 91 antivirus and URL‑reputation engines, none of which raised a detection at the time of analysis. The listed threat type is a crypto drainer, suggesting the site attempts to illicitly acquire cryptocurrency assets from victims.
Current intelligence marks the domain as still active, and no evidence of takedown or sink‑hole operation has been reported. No SSL certificate details, HTTP response codes, or page‑title metadata are available in the collected data, limiting visibility into the service layer. The absence of additional detections does not imply benign intent, and the presence on a blocklist combined with the crypto‑drainer classification warrants precautionary measures.
Defenders should consider adding the domain and its resolving IP address to outbound‑traffic deny lists, enforce DNS‑level filtering, and monitor Netlify‑associated traffic for anomalous patterns. Continuous re‑scanning with multi‑engine services is recommended to capture any future changes in the threat profile. Organizations that handle cryptocurrency transactions should treat any interaction with this domain as high risk and isolate affected endpoints for forensic analysis.