Analysis of blastpools.xyz, first observed on July 28 2026, indicates that the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently hosted on the IP address 104.21.31.81, which is associated with Cloudflare's edge network. The authoritative nameservers are lindsey.ns.cloudflare.com and stan.ns.cloudflare.com, confirming the use of Cloudflare's DNS service. The domain has been classified as a generic phishing threat and is listed as active.
It is currently blocked by the PhishDestroy sinkhole and appears on one external security blocklist, demonstrating that at least one third‑party repository has flagged the domain for malicious use. VirusTotal scanned the domain with 91 AV engines; none of the engines reported a detection at the time of the scan, but the absence of detections does not constitute a safety assurance. No additional intelligence such as Safe Browsing status, OTX mentions, SSL certificate details, HTTP response codes, or page title has been disclosed, leaving the surface‑web content unverified.
The limited data set prevents a full attribution of the campaign’s infrastructure, but the recent registration date and rapid deployment suggest an opportunistic phishing operation likely targeting users through credential‑stealing pages. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any new IP resolutions or DNS changes, and incorporate the domain hash into threat‑intel feeds. Ongoing observation of related Cloudflare‑served IP ranges and periodic re‑scanning with multi‑engine services are recommended to detect any future malicious payloads or changes in behavior.