Analysis of felixprotocol.click, first observed on June 20, 2026, indicates an active generic phishing infrastructure. The domain is registered through Dynadot, LLC and is delegated to the Cloudflare nameservers fred.ns.cloudflare.com and kami.ns.cloudflare.com. DNS resolution points to the IP address 104.21.53.194, which belongs to Cloudflare’s edge network, a common hosting choice for fast‑flux or proxy‑based phishing sites.
VirusTotal has recorded five positive detections out of ninety‑one scanned vendors, confirming that multiple security products have identified malicious behavior associated with the domain. The same domain appears on three independent blocklists—PhishDestroy, MetaMask, and SEAL—demonstrating that it has been flagged by both anti‑phishing and cryptocurrency‑focused defenses. The current status remains active, and no additional intelligence such as SSL certificate details, HTTP response codes, or content analysis has been published, leaving the exact payload and targeted brand unspecified.
Defenders should proactively block felixprotocol.click at DNS and proxy layers, monitor outbound connections to its resolved IP, and include the domain in endpoint detection rules. Continuous re‑query of public threat‑intel feeds is advised to capture any future changes, such as additional blocklist listings or an increase in vendor detections. Until further content analysis becomes available, the domain should be treated as high‑risk and excluded from user‑facing services.