Analysis of trusted-premium.org indicates active phishing infrastructure with characteristics requiring defensive attention. The domain was registered on July 24, 2026, through Fewmoretaps OU operating as Trustname.com, a registrar frequently observed in phishing campaigns. It currently resolves to IP address 172.67.174.2, which is part of Cloudflare's network, a common hosting choice for threat actors seeking to obscure origin and evade IP-based blocking. Nameservers cameron.ns.cloudflare.com and serena.ns.cloudflare.com further confirm Cloudflare's role in the domain's DNS resolution. As of July 28, 2026, the domain remains active and is flagged on one security blocklist by PhishDestroy, suggesting preliminary detection of malicious intent.
No additional blocklist entries or vendor detections are currently recorded. A VirusTotal scan conducted by 91 security vendors returned no detections; however, this absence does not confirm the domain's safety and should not be interpreted as an all-clear. Phishing domains often evade initial detection, particularly when infrastructure is newly deployed or employs evasion techniques. The exact content and target of the phishing operation hosted on trusted-premium.org have not been analysed.
No brand, page title, or phishing kit has been identified in available intelligence, and no specific scam category (e.g., credential harvesting, payment fraud, or crypto-related) can be confirmed at this stage. Defenders are advised to treat the domain as suspicious based on its recent registration, Cloudflare-hosted infrastructure, and single blocklist flag. Network-level blocking or monitoring is recommended for organisations until further analysis clarifies the threat profile. Continuous monitoring of detection status across security vendors is warranted, as additional flags may emerge as the campaign matures.