Analysis of ref67731-crypto-app.com indicates that the domain is actively being used for phishing. The domain was registered on July 29, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently pointing to the IP address 172.67.171.18, which is served by Cloudflare name servers dell.ns.cloudflare.com and nash.ns.cloudflare.com. The site has been added to three public security blocklists and is flagged by the PhishDestroy, MetaMask, and SEAL blocklists, confirming its malicious intent.
VirusTotal scans show that 2 of 91 security vendors have identified the domain as malicious, providing additional corroboration. The domain’s risk level is assessed as high, and its status remains active as of the report date, July 30, 2026. No further public intelligence, such as page title or SSL certificate details, is available at this time, leaving the exact phishing lure and targeted brand undefined.
Defenders should immediately block ref67731-crypto-app.com at the network perimeter, update DNS filtering policies, and ensure endpoint protection solutions incorporate the known blocklist entries. Continuous monitoring of the associated IP address and Cloudflare name servers is recommended, as the infrastructure may be leveraged for additional malicious domains. Organizations should also consider reporting any observed traffic to the relevant blocklist operators to reinforce collective defenses.