MALICIOUS — CRITICAL
Проверка домена order.rounitrade.com на фишинг и безопасность
order[.]
This domain, order.rounitrade.com, is identified as a brand impersonation threat specifically targeting American Express customers.
- VirusTotal
- 12/91
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
order.rounitrade.com — Контент недоступен (HTTP 502). Олицетворение бренда: American express; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 12/91 (BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
This domain, order.rounitrade.com, is identified as a brand impersonation threat specifically targeting American Express customers. The infrastructure is designed to deceive users into believing they are interacting with an official American Express platform, potentially leading to unauthorized disclosure of sensitive financial credentials, personal information, or payment details. The page title, 'Vinted | Compra y vende ropa en una comunidad elegante,' is incongruent with the purported brand, indicating either misconfiguration or deliberate obfuscation to evade detection while maintaining operational infrastructure for malicious campaigns. Analysis of technical indicators reveals multiple red flags. The domain is flagged by 12 out of 95 security vendors on VirusTotal, a significant detection rate that underscores its malicious nature. It was registered through Dynadot LLC on December 01, 2025, suggesting recent creation for short-term malicious use. The domain resolves to the IP address 188.114.96.3, hosted on Cloudflare’s network (AS13335), a common tactic to obscure hosting origins and complicate takedown efforts. Additionally, the domain appears on one security blocklist, and no SSL certificate is present, further degrading its legitimacy. The current status is offline, but the infrastructure may be reactivated or repurposed for future attacks. Users who visited order.rounitrade.com should take immediate remedial actions. If any credentials, payment details, or personal information were entered, affected individuals should contact American Express directly to report potential fraud and request account monitoring or freezing. All passwords associated with the compromised information should be changed, and multi-factor authentication should be enabled on all critical accounts. Devices used to access the domain should be scanned for malware using updated security tools. Users are advised to monitor financial statements for unauthorized transactions and consider placing a fraud alert or credit freeze with major credit bureaus to mitigate identity theft risks. Given the elevated risk level, vigilance is recommended even if no immediate signs of compromise are observed.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: rounitrade.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain rounitrade.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.