Analysis of ruamox.com, created on July 25, 2026, shows that the domain resolves to the Cloudflare‑hosted address 172.67.213.50. Registration details list Fewmoretaps OU d/b/a Trustname.com as the registrar, and the authoritative name servers are gabriella.ns.cloudflare.com and peyton.ns.cloudflare.com. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy service, indicating that at least one mitigation platform has identified it as malicious. VirusTotal records reveal that the domain was examined by 91 independent scanning engines, none of which generated a detection at the time of analysis; this absence of alerts does not constitute a safety guarantee.
No public evidence of Safe Browsing, OTX, SSL certificate details, HTTP response codes, trust scores, or page titles is currently available, leaving those aspects unverified. The limited visibility suggests that the site may be operating with minimal exposure or that data collection pipelines have not yet captured its content. Defenders should continue to monitor ruamox.com, enforce blocklist rules that include the domain, and consider adding it to internal URL filtering policies.
Given its recent registration and the presence of Cloudflare infrastructure, the domain could be leveraged for credential harvesting or other phishing‑related activities. Organizations are advised to enforce MFA, educate users about unsolicited login prompts, and inspect outbound traffic for connections to 172.67.213.50. Ongoing surveillance of detection vendor updates and blocklist expansions is recommended to capture any future changes in the domain’s threat posture.