rosenblattpremium[.]com
“Welcome to | Rosenblatt Premium”
rosenblattpremium.com — Conteúdo indisponível (HTTP 502). Representação da marca: Google; Tipo de golpe: Tech Support Scam. Resumo das evidências: VirusTotal 5/93 (alphaMountain.ai, CyRadar, Fortinet, Gridinsoft, Webroot); PhishDestroy score 65/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Rosenblattpremium.com was registered on 21 February 2026 and resolves to the IPv4 address 107.172.61.186, which belongs to AS36352 HostPapa in the United States. The domain is currently taken offline, but historical scans show it was actively serving content before removal. The site presented the page title “Welcome to | Rosenblatt Premium” and was identified as a tech‑support scam that impersonates Google. No legitimate Google branding appears in the title, indicating the impersonation is limited to textual claims. The SSL certificate issued for the host is identified only as “R11”, providing no further validation of the certificate authority.
Multiple security services have flagged the domain. VirusTotal recorded five detections out of ninety‑three scanners, and the Gridinsoft trust score assigned a rating of 0 / 100, the lowest possible confidence level. The domain appears on a single external blocklist and is explicitly listed by the PhishDestroy service as malicious. These indicators collectively suggest a high likelihood of malicious intent. Because the domain’s hosting provider, HostPapa, is a shared‑hosting environment, the same IP address may be reused by unrelated legitimate sites, so care must be taken when applying IP‑based blocks.
However, the combination of a low trust score, multiple vendor detections, and the confirmed tech‑support scam classification justifies adding the domain name itself to deny‑list rules across email gateways, web proxies, and DNS filtering solutions. Defenders should also monitor traffic to 107.172.61.186 for any residual activity and consider tightening outbound rules that could allow communication with the host. Open questions remain regarding the full payload delivered by the site, the exact phishing kit used, and whether additional infrastructure (such as command‑and‑control servers) is associated with the same IP range.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo