rollbux.com was registered on July 11, 2025 through GoDaddy.com, LLC and currently uses the Cloudflare nameservers edward.ns.cloudflare.com and lila.ns.cloudflare.com. The domain resolves to the IP address 104.21.2.64, which is part of Cloudflare's global edge network. As of August 01, 2026 the domain remains active and has been identified by the PhishDestroy blocklist, where it appears on a single security blocklist entry.
VirusTotal records indicate that the domain has been scanned by 91 antivirus and URL‑reputation vendors; none of those scanners raised a detection at the time of analysis. No additional public reputation sources such as Safe Browsing or OTX are referenced in the available intelligence, and no SSL certificate details or HTTP response codes have been disclosed. The limited evidence points to a typical phishing infrastructure: a recently created domain, rapid deployment on a widely used CDN, and inclusion on at least one phishing‑specific blocklist.
Uncertainty remains around the specific phishing campaign payload, targeted brand, and whether the site actively hosts credential‑capture pages, because page‑title or content analysis has not been provided. Defenders should add rollbux.com to URL filtering rules, monitor outbound DNS queries for the associated Cloudflare IP range, and consider sharing the indicator with threat‑sharing communities. Ongoing observation of the domain’s activity, especially any changes to DNS records or new blocklist listings, is recommended to assess whether the threat evolves or expands.