Analysis of rozshuk.com, created 13 November 2025, shows it is currently active and associated with a generic phishing campaign. The domain resolves to IP 178.16.54.253 and uses the nameservers ns1.virtualine.org and ns2.virtualine.org, both typical of shared hosting environments. Registration was performed through CNOBIN INFORMATION TECHNOLOGY LIMITED, a registrar that does not provide privacy protection, allowing registrant details to be queried. The domain appears on a single security blocklist and has been flagged by the PhishDestroy feed, indicating that at least one reputable anti‑phishing service has observed malicious activity linked to the host.
VirusTotal records show that the domain was scanned by 91 vendors; none of the scanners raised a detection at the time of analysis, but the absence of a flag does not constitute evidence of benign intent. No public SSL certificate details, HTTP response codes, page title, or content snapshots are available, leaving the precise phishing lure and targeted brand undefined. The limited visibility of the site’s content means that the specific credential‑stealing technique, victim profile, and any payload delivery mechanisms remain uncertain.
Defenders should treat rozshuk.com as a high‑confidence phishing indicator and block network connections to the domain and its resolved IP address. Monitoring of the associated nameservers and registrar for new domains using the same infrastructure is advised, as is periodic re‑scanning with sandbox and URL reputation services to capture any changes in payload or hosting. Inclusion of the domain in internal allow‑list exceptions should be avoided until a thorough forensic examination confirms the absence of malicious activity.