The domain web3-ai01.top was registered on July 28, 2026 through Dynadot LLC and is currently served by the authoritative name servers ns1.dyna-ns.net and ns2.dyna-ns.net. DNS resolution points the domain to the IPv4 address 85.137.57.218. The hosting IP is listed on two public phishing blocklists, PhishDestroy and SEAL, indicating that the address has been associated with malicious activity and is being actively filtered by security products that rely on these feeds.
A VirusTotal scan performed by 91 anti‑malware engines returned no detections at the time of analysis; this absence of signatures does not constitute a safety guarantee but does provide a baseline for future comparative scans. No additional intelligence such as SSL certificate details, HTTP response codes, page title, or known phishing kit identifiers is available, leaving the exact content and operational tactics of the site unverified. The registrar and nameserver information are legitimate and do not, on their own, suggest compromise, yet the rapid creation date coupled with immediate blocklist listings points to a likely pre‑configured malicious deployment.
Defenders should add the domain and its resolving IP to local deny lists, monitor DNS queries for repeated lookups, and perform periodic rescans on VirusTotal or similar platforms to capture any future payload changes. Continuous observation of the IP’s reputation across threat intel feeds is recommended, as the current evidence is limited to blocklist presence and registration metadata.