roverify[.]cc
“RoVer”
Detecção armazenada
Alerta de cloaking
- Tipo de cloaking
status_split- Pontuação de cloaking
- 2/6
Resumo das evidências
The domain roverify.cc, registered on May 30 2026 through Hosting Concepts B.V. d/b/a Registrar.eu, is currently classified as a high‑risk credential phishing site. Google Safe Browsing lists it under the SOCIAL_ENGINEERING category, and VirusTotal reports that eight of ninety‑five scanned security vendors have flagged the domain as malicious. The site returns an HTTP 302 redirect and presents the page title “RoVer”, matching the observed credential‑phishing landing page. Infrastructure analysis shows the domain resolves to IP 91.240.20.15, which is allocated to Hooray Solutions Corp. in the Netherlands. The hosting provider is identified by the nameservers ns1.eggywall.org and ns2.eggywall.cc. The TLS certificate is issued by Let’s Encrypt (certificate identifier E8), indicating a legitimate certificate authority but offering no protection against the underlying fraudulent content. Threat intelligence feeds have already added roverify.cc to at least one security blocklist, and the domain is blocked by PhishDestroy. The active status and the high‑risk rating suggest ongoing exploitation, likely targeting users seeking verification services. The combination of a recent registration date, a short‑lived TLS certificate, and the redirection behavior aligns with typical credential‑phishing campaigns that aim to harvest login credentials. Uncertainty remains regarding the full scope of the phishing campaign, including the specific brands or login portals impersonated and the extent of victim exposure. Defenders should prioritize blocking the resolved IP address 91.240.20.15 and the domain roverify.cc at the network perimeter, enforce URL filtering based on the Google Safe Browsing flag, and monitor for the associated nameservers. Continuous re‑evaluation of VirusTotal and other vendor detections is advised to capture any escalation in detection counts.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo