Analysis of multichain-dapps.pro, created on July 28 2026 and hosted on Cloudflare infrastructure (IP 104.21.65.90, nameservers cass.ns.cloudflare.com and miles.ns.cloudflare.com), shows multiple indicators of malicious phishing activity. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, and as of the report date (July 30 2026) it remains active. VirusTotal records indicate that 6 of 91 security vendors have flagged the domain, reflecting a modest but notable detection rate. Independent blocklists used by PhishDestroy, MetaMask, and SEAL have already listed the domain, and it appears on three additional security blocklists, reinforcing the consensus that the site is employed for credential‑stealing or fraudulent transactions.
The risk rating assigned is high, consistent with the presence of active blocking and vendor detections. The observable infrastructure points to a typical phishing deployment: a recently registered domain, rapid provisioning on a shared CDN service, and immediate inclusion in anti‑phishing feeds. No public SSL certificate details, page title, or content analysis are available in the current intelligence set, leaving the exact lure or targeted brand undefined. Consequently, defenders cannot confirm the specific phishing template or victim profile, but the corroborated detections justify proactive mitigation.
Recommended actions include adding 104.21.65.90 and multichain-dapps.pro to network‑level deny lists, updating endpoint and browser protection suites with the latest blocklist feeds, and monitoring for any future DNS or TLS certificate changes that might indicate a shift in hosting. Continuous watch of VirusTotal and other reputation services is advised to capture additional vendor votes should the campaign evolve. Until further evidence emerges, the domain should be treated as a confirmed high‑risk phishing source.