Analysis as of July 30, 2026 shows that the domain inkchaindocusign.icu remains active and is being leveraged for a generic phishing operation. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and its creation timestamp is July 21, 2026, indicating a very recent deployment. Authoritative DNS resolution points to the IPv4 address 104.21.75.49, and the domain is served by Cloudflare name servers beau.ns.cloudflare.com and indie.ns.cloudflare.com, suggesting the use of Cloudflare’s edge network for traffic obfuscation and potential DDoS mitigation.
The domain appears on three independent security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the consensus that it is malicious. VirusTotal analysis reports that three of ninety‑one scanning engines have flagged the domain, providing additional corroboration of its threat profile. No public evidence of the landing page content, SSL certificate details, or HTTP response codes is available from the supplied intelligence, leaving the exact phishing lure and credential capture mechanisms unverified.
Defenders should continue to block the domain at network perimeters, update endpoint and browser protection signatures, and monitor for any outbound connections to the resolved IP address. Because the domain leverages Cloudflare’s infrastructure, attackers may rapidly shift hosting or employ additional subdomains, so continuous re‑evaluation of DNS and IP reputation is advised. Organizations that rely on email or web access to the target brand should educate users about unsolicited communications that reference the domain, and incident response teams should be prepared to isolate compromised accounts should credential harvesting be confirmed.