Analysis conducted on 30 July 2026 identifies proposals-fwa.fun as an active generic phishing infrastructure. The domain was registered on 28 July 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is delegated to Cloudflare name servers elisabeth.ns.cloudflare.com and rodrigo.ns.cloudflare.com. DNS resolution points to the IP address 172.67.155.105, an address commonly associated with Cloudflare’s content‑delivery network. The domain appears on three independent security blocklists, specifically PhishDestroy, MetaMask, and SEAL, indicating that multiple threat‑intelligence feeds have flagged it as malicious. VirusTotal reports that the domain has been scanned by 91 antivirus and URL‑reputation vendors; at the time of analysis no vendor flagged the domain as malicious.
The absence of detections does not constitute assurance of safety, especially given the recent registration date and blocklist presence. No public SSL certificate details, HTTP response codes, or page‑title information were available at the time of review, leaving the content of the site unverified. At present, the site’s landing page, target brand, and any credential‑harvesting forms have not been captured, so the exact phishing vector remains unknown. Analysts should treat any emails or messages referencing proposals-fwa.fun with heightened suspicion and employ URL‑rewriting or sandbox analysis before allowing user interaction.
Given the combination of a newly created domain, Cloudflare hosting, and blocklist inclusion, the infrastructure aligns with typical phishing campaigns that exploit trusted CDN services to hide malicious endpoints. Defenders should add proposals-fwa.fun to network‑level deny lists, enforce DNS‑based filtering, and monitor outbound connections to the associated IP address. Continuous re‑scanning with sandbox and URL‑reputation services is recommended to capture any future payloads or content changes.