Analysis of the domain proposal-redstone.info, observed on July 30, 2026, indicates that it is actively leveraged in a high‑risk generic phishing campaign. The domain was registered on July 28, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and remains active. Its authoritative name servers are alla.ns.cloudflare.com and todd.ns.cloudflare.com, and DNS resolution points to the IP address 104.21.82.101, a Cloudflare‑hosted endpoint commonly used for fast‑flux or proxy services.
VirusTotal scans show that three of ninety‑one security vendors have flagged the domain, providing independent confirmation of malicious intent. The domain is listed on three security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its reputation as a phishing source. No additional public intelligence such as Safe Browsing verdicts, OTX references, SSL certificate details, HTTP response codes, or page‑title metadata is currently available, leaving the full scope of the hosted content unverified.
Defenders should treat any traffic to proposal‑redstone.info as hostile: network perimeter devices should block outbound connections to the associated IP, DNS filtering solutions should deny resolution of the domain, and endpoint protection platforms should incorporate the three vendor detections into their threat‑intel feeds. Continuous monitoring for new blocklist entries or additional vendor detections is recommended to capture any evolution of the campaign.