Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@spaceship.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
roverauthorize[.]link
roverauthorize.link 网络钓鱼与安全检查
“RoVer”
roverauthorize.link — 最后已知的活跃状态 (HTTP 200). 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 27 alerts; Google Safe Browsing flagged; PhishDestroy score 100/100. 注册商: Spaceship.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, roverauthorize.link, is actively flagged as a high-risk credential phishing site targeting users through a page titled 'RoVer.' Registered on April 18, 2026, via Spaceship, Inc., the domain resolves to IP address 35.157.26.135, hosted on AWS EC2 infrastructure in Germany (eu-central-1). Analysis indicates the use of React and Netlify technologies, alongside HSTS implementation, which may attempt to lend legitimacy to the phishing page. The SSL certificate is issued by Let's Encrypt (E8), a common choice for both legitimate and malicious sites. Infrastructure review reveals the domain is served by four nameservers under NS1 (dns1.p01.nsone.net through dns4.p01.nsone.net), a configuration consistent with bulletproof or reseller-hosted setups. Google Safe Browsing has classified the site as engaging in social engineering, and it appears on at least one security blocklist. Eleven of 94 security vendors on VirusTotal have flagged the domain, though the exact detection context remains unverified without deeper analysis. The scam type is explicitly credential phishing, though the specific brand or platform being impersonated is not confirmed in available data. No known phishing kit or unique campaign identifier has been linked to this domain at this time. Defenders should treat roverauthorize.link as an active threat, block access at the network level, and monitor for credential harvesting attempts originating from this infrastructure. Further investigation into connected domains or IPs may reveal broader campaign activity.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | roblox.gf |
malicious | Sinkholed |
| OpenDNS | roblox.gf |
phishing | Phishing Block |
| Hagezi Threat Feed | roblox.gf |
malicious | Sinkholed |
| Quad9 DNS | roblox.gf |
malicious | Sinkholed |
| DNS4EU | roblox.gf |
malicious | Sinkholed |
| Cloudflare DNS | roblox.com.ps |
malicious | Sinkholed |
| DNS4EU | roblox.com.ps |
malicious | Sinkholed |
| DNS4EU | roblox.al |
malicious | Sinkholed |
| DNS4EU | robloxs.icu |
malicious | Sinkholed |
| OpenDNS | roblox.gs |
phishing | Phishing Block |
| DigiCert UltraDNS | roblox.gs |
malicious | Sinkholed |
| Hagezi Threat Feed | roblox.gs |
malicious | Sinkholed |
| DNS4EU | roblox.gs |
malicious | Sinkholed |
| Quad9 DNS | roblox.gs |
malicious | Sinkholed |
| DigiCert UltraDNS | roblox.cd |
malicious | Sinkholed |
| DNS4EU | roblox.cd |
malicious | Sinkholed |
| OpenDNS | roblox.cd |
phishing | Phishing Block |
| Hagezi Threat Feed | roblox.cd |
malicious | Sinkholed |
| Cloudflare DNS | roblox.cd |
malicious | Sinkholed |
| Quad9 DNS | roblox.cd |
malicious | Sinkholed |
| Hagezi Threat Feed | kto.gold |
malicious | Sinkholed |
| DNS4EU | kto.gold |
malicious | Sinkholed |
| Cloudflare DNS | roblox.com.py |
malicious | Sinkholed |
| OpenDNS | roblox.com.py |
phishing | Phishing Block |
| DigiCert UltraDNS | roblox.com.py |
malicious | Sinkholed |
| DNS4EU | roblox.com.py |
malicious | Sinkholed |
| Quad9 DNS | roblox.com.py |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 3 identified
JavaScript library for building user interfaces with component-based architecture.
Platform for deploying and hosting modern web applications.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of roverauthorize.link · checked Apr 18, 2026
证据与外部报告
PD-20260418-681DBC Recipient: abuse@spaceship.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。