home.rouzax.com is currently active and has been identified as a high‑risk credential‑harvesting site. The domain was registered on July 20 2026 through Fewmoretaps OU d/b/a Trustname.com. It resolves to the IPv4 address 64.7.198.11 and uses Cloudflare DNS resolvers amy.ns.cloudflare.com and lex.ns.cloudflare.com, which can obscure the true hosting environment. The infrastructure is listed on one public security blocklist and has been added to the PhishDestroy blocklist, indicating that at least one reputable anti‑phishing service is already filtering traffic to the host.
VirusTotal analysis shows that 11 of 91 scanned security engines flag the domain as malicious, providing independent corroboration of its malicious intent. No public safe‑browsing or OTX entries were supplied, and the page title and content have not been disclosed, so the exact lure or targeted brand cannot be confirmed at this time. The rapid creation‑to‑detection window (seven days) suggests an automated campaign that leverages newly registered domains to evade reputation‑based defenses. Defenders should immediately block DNS resolution to home.rouzax.com and the associated IP address 64.7.198.11 at network perimeters, add the domain to internal URL filtering lists, and monitor for any outbound connections to the host.
Because the domain uses Cloudflare’s nameservers, further investigation of the origin server may require querying behind‑the‑scenes services or reviewing TLS certificates if presented. Continuous re‑scanning with multi‑engine services such as VirusTotal is recommended to capture any changes in the detection score. Organizations that rely on credential‑based authentication should enforce multi‑factor authentication and educate users about unsolicited login requests that reference suspicious URLs. The combination of recent registration, multiple vendor detections, and inclusion on a known phishing blocklist justifies the high‑risk classification and warrants proactive mitigation.