ruxbl-2new[.]blogspot[.]com
“Blogia ei löydy”
ruxbl-2new.blogspot.com — Conteúdo indisponível. Representação da marca: ["google"]. Resumo das evidências: VirusTotal 16/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); CF Radar malicious; PhishDestroy score 95/100. Registrador: MarkMonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain ruxbl-2new.blogspot.com was registered on 21 February 2026 through MarkMonitor, Inc. and points to the IPv6 address 2a00:1450:4001:808::2001, which belongs to Google LLC (AS15169) and resolves to a location in Germany. The site is hosted on the Blogger platform, as indicated by the nameserver blogspot.l.googleusercontent.com and the detection of Blogger‑related technologies. Additional observed components include Java, Python, OpenGSE, and support for HTTP/3, suggesting a standard Blogger environment rather than a bespoke malicious kit. The SSL certificate presented is issued by Google Trust Services under the WE2 profile, consistent with legitimate Google‑hosted sites. When accessed, the server returned HTTP 404 and the page title “Blogia ei löydy”, Finnish for “Blog not found”.
This response indicates that the content has been removed or the domain is currently inactive. Nevertheless, the domain appears on a single security blocklist, PhishDestroy, and 16 of 95 VirusTotal scanners flagged it, reflecting some level of suspicion despite the offline status. Current intelligence gaps include the exact phishing payload or lure, the targeted brand or service, and any malicious redirects that may have been present before takedown. Analysts have not observed any credential‑harvesting forms or malicious scripts, and the page content has not been captured. Consequently, it is unclear whether the domain was used for a targeted credential‑stealing campaign or as a placeholder for future malicious activity.
Defenders should continue to block the domain at perimeter defenses and monitor for any resurgence of activity. Given the Google‑hosted infrastructure, standard URL filtering and DNS sinkholing can be applied without risking disruption of legitimate Blogger services. Threat‑intel feeds should be updated to retain the blocklist entry, and any future resolutions to the same IPv6 address should be scrutinized.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 100% de confiançaJava is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 100% de confiançaOpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ruxbl-2new.blogspot.com · checked Mar 2, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo