rosenblattpremium[.]com
“Welcome to | Rosenblatt Premium”
证据摘要
Rosenblattpremium.com was registered on 21 February 2026 and resolves to the IPv4 address 107.172.61.186, which belongs to AS36352 HostPapa in the United States. The domain is currently taken offline, but historical scans show it was actively serving content before removal. The site presented the page title “Welcome to | Rosenblatt Premium” and was identified as a tech‑support scam that impersonates Google. No legitimate Google branding appears in the title, indicating the impersonation is limited to textual claims. The SSL certificate issued for the host is identified only as “R11”, providing no further validation of the certificate authority.
Multiple security services have flagged the domain. VirusTotal recorded five detections out of ninety‑three scanners, and the Gridinsoft trust score assigned a rating of 0 / 100, the lowest possible confidence level. The domain appears on a single external blocklist and is explicitly listed by the PhishDestroy service as malicious. These indicators collectively suggest a high likelihood of malicious intent. Because the domain’s hosting provider, HostPapa, is a shared‑hosting environment, the same IP address may be reused by unrelated legitimate sites, so care must be taken when applying IP‑based blocks.
However, the combination of a low trust score, multiple vendor detections, and the confirmed tech‑support scam classification justifies adding the domain name itself to deny‑list rules across email gateways, web proxies, and DNS filtering solutions. Defenders should also monitor traffic to 107.172.61.186 for any residual activity and consider tightening outbound rules that could allow communication with the host. Open questions remain regarding the full payload delivered by the site, the exact phishing kit used, and whether additional infrastructure (such as command‑and‑control servers) is associated with the same IP range.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控