Analysis of solairdrops-gl.netlify.app, observed on July 29, 2026, shows infrastructure consistent with a crypto‑drainer operation. The domain is hosted on Netlify, a popular static‑site and serverless platform, and resolves to the IPv4 address 63.176.8.218. No nameserver records were returned (NS_NOT_FOUND), indicating that standard DNS delegation information is unavailable, which can hinder rapid takedown or sink‑hole efforts. The site was scanned by VirusTotal using 91 antivirus and URL‑reputation engines; none reported a detection, but the absence of alerts does not guarantee benign behavior and should be interpreted only as a lack of current signatures.
The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy service, suggesting that at least one external monitoring entity has identified malicious activity associated with the host. The registrar information confirms registration through Netlify, a service that often provides short‑lived or disposable sites for malicious actors. No additional intelligence such as SSL details, HTTP response codes, page titles, or brand references is presently available, leaving the exact payload or lure used by the crypto‑drainer unknown.
Given the active status of the domain, its presence on a blocklist, and its association with a known threat type, defenders should treat the domain as hostile. Recommended actions include adding the domain to internal block or deny lists, monitoring outbound traffic for connections to 63.176.8.218, and employing URL‑filtering solutions that reference the PhishDestroy block. Further investigation should focus on retrieving the live page content, capturing HTTP headers, and analyzing any scripts or redirects to identify the specific cryptocurrency wallets or transaction mechanisms employed.