On July 30, 2026, the domain ref87731-crypto-app.com was examined following its classification as a high‑risk generic phishing site. The domain was registered on July 29, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and remains active. DNS resolution points to the IP address 188.114.97.3, and the authoritative nameservers are alan.ns.cloudflare.com and sloan.ns.cloudflare.com, indicating the use of Cloudflare's DNS infrastructure.
VirusTotal reports that two out of ninety‑one scanning engines have flagged the domain, providing limited but notable malicious indication. The domain is listed on three external blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the consensus that it is being used for phishing purposes. No public SSL certificate details, HTTP status codes, or page title information are currently available, limiting the depth of content‑level analysis.
The observable infrastructure—recent registration, Cloudflare nameservers, and the modest detection count—suggests a fast‑flux or throwaway deployment typical of credential‑harvesting campaigns. Defenders should add ref87731-crypto-app.com to network and endpoint blocklists, monitor DNS queries for the associated IP, and consider extending coverage in email security gateways to capture any associated phishing attempts. Ongoing observation is recommended to capture any future changes in hosting, detection rates, or additional intelligence that may clarify the threat actor's tactics.