Analysis of the subdomain usa-rbx.blogspot.com shows it is registered through Google LLC. DNS resolution points to the IPv4 address 142.251.14.132, which is part of Google’s public cloud infrastructure. The domain is currently listed on one security blocklist and has been explicitly blocked by the PhishDestroy service, indicating that at least one external mitigation platform has identified malicious activity associated with it. VirusTotal records show that the URL was submitted to 91 scanning engines, none of which produced a positive detection; this absence of flags does not constitute evidence of benign behavior.
No nameserver information is available, and no additional metadata such as SSL certificate details, HTTP response codes, or page title has been published in the available intelligence. Consequently, the precise phishing lure, target brand, or credential‑capture mechanism remains unknown. Defenders should treat the domain as hostile until further analysis clarifies its payload.
Recommended actions include adding the full host name to URL‑filtering or proxy block lists, monitoring DNS queries for internal resolutions to the Google IP, and triggering sandbox analysis of any downloaded content if a request to the domain is observed. Because the hosting IP belongs to a large cloud provider, IP‑based blocking may cause collateral disruption and is therefore discouraged in favor of host‑level controls. Continuous ingestion of updated blocklist feeds and periodic re‑query of VirusTotal or similar reputation services is advised to capture any future changes in the domain’s classification.