The domain rpc-resolve.pro was registered on July 21, 2026 through Name.com, Inc. and is currently active. DNS resolution points exclusively to the IPv4 address 64.29.17.65, which is served by the authoritative name servers ns1.vercel-dns.com and ns2.vercel-dns.com. The infrastructure has been observed on three external security blocklists, indicating that multiple threat‑intelligence feeds have already flagged the domain for malicious use. Independent analysis on VirusTotal shows that four of ninety‑one scanning engines have returned a positive detection, reinforcing the suspicion of illicit activity.
Defensive products such as PhishDestroy, MetaMask, and SEAL have explicitly blocked the domain, confirming that at least three security solutions consider it a threat. The available data does not include a page title, SSL certificate details, HTTP response codes, or any observed payload, so the exact phishing vector, targeted brand, or malicious kit remains undefined. Evidence therefore consists of registration metadata, DNS configuration, blocklist presence, and limited vendor detections.
Given the recent creation date, the active status, and the existing blocklist entries, security teams should prioritize immediate containment by adding rpc-resolve.pro to local deny lists, updating DNS filtering policies, and monitoring outbound traffic for connections to 64.29.17.65. Continuous re‑evaluation is advised, as further analysis may reveal additional indicators such as specific phishing content, credential‑stealing forms, or malware delivery mechanisms. Organizations that rely on real‑time threat‑intelligence feeds should ensure that their feeds ingest the latest blocklist updates referencing this domain to reduce exposure to the ongoing campaign.