rasowin.com was registered on July 22 2026 through the corporate entity Fewmoretaps OU doing business as Trustname.com. The domain is delegated to the Cloudflare name servers chance.ns.cloudflare.com and delilah.ns.cloudflare.com and resolves to the IPv4 address 64.7.198.11. Within a week of creation the domain appeared on three public blocklists and is currently listed by PhishDestroy, MetaMask and SEAL, indicating active mitigation by multiple threat‑intelligence feeds. VirusTotal has analyzed the domain and 17 of 91 scanned security vendors returned a malicious classification, reinforcing the high‑risk assessment.
The short lifespan, immediate blocklist inclusion, and multi‑vendor detections are consistent with a newly deployed phishing infrastructure. No additional public data such as SSL certificate details, HTTP response codes, page title, or content snapshots have been published, so the specific phishing lure or target brand remains unknown. Defenders should add 64.7.198.11 to network‑level deny lists, enforce DNS blocking of rasowin.com, and monitor for any outbound connections to the associated Cloudflare name servers.
Continuous re‑scanning on VirusTotal or similar sandboxes is advisable to capture any evolving payloads. Organizations using corporate web filtering, endpoint detection and response, and email security gateways should ensure the domain is included in their block lists to prevent credential harvesting attempts. The rapid appearance on blocklists and multi‑vendor flagging suggest the infrastructure is actively used and should be treated as a high‑severity threat until takedown or further intelligence is obtained.