premixajs[.]online
“Google Chrome - The Fast & Secure Web Browser Built to be Yours”
The domain premixajs.online was identified as a phishing site engaged in brand impersonation, specifically targeting Google's identity. This domain presented itself as an official Google Chrome download page, using the page title 'Google Chrome - The Fast & Secure Web Browser Built to be Yours.' The site has since been taken offline, but it previously posed an elevated risk to users searching for legitimate Google services by attempting to deceive them with a fraudulent interface.
Technical analysis shows that premixajs.online was registered through NameCheap, Inc. on March 12, 2026. It resolved to the IP address 188.114.97.3, located in the US under AS13335 (Cloudflare, Inc.), and used nameservers merlin.ns.cloudflare.com and sharon.ns.cloudflare.com. The SSL certificate was issued by Google Trust Services / WE1. VirusTotal reported that 1 of 95 security vendors, specifically Gridinsoft, flagged this domain as malicious. Additionally, it appeared on one security blocklist (PhishDestroy), though Google Safe Browsing did not flag it.
Anyone who interacted with premixajs.online while it was active should immediately change any passwords entered on the site and enable two-factor authentication on affected accounts. Users should also monitor their accounts for unauthorized activity and report any suspicious incidents to Google's official support channels. Reporting phishing domains like premixajs.online to security organizations and blocklist maintainers can help protect others from similar impersonation scams.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
PD-1773324407-premixajs.onlin Recipient: abuse@namecheap.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive