Analysis of uus-robinhood-apli.gitbook.io shows a high‑risk phishing indicator set as active on July 31, 2026. The domain resolves to IP address 104.18.40.47, which is hosted behind Cloudflare’s network (nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com). Registration data indicates the domain was created on March 30, 2014 and is currently registered through Cloudflare, Inc, a common service used by both legitimate sites and malicious actors to obscure origin. The domain appears on one security blocklist and is explicitly blocked by PhishDestroy, confirming that at least one reputable anti‑phishing feed has identified it as malicious.
VirusTotal scans report that 4 of 91 security vendors flag the domain, providing additional vendor‑level corroboration of malicious intent. No public Safe Browsing, OTX, or SSL/TLS certificate details are available in the supplied intelligence, and the page title or content has not been disclosed, leaving those surface‑level indicators unverified. Defenders should treat any traffic to this domain as hostile.
Recommended actions include adding the domain to outbound deny lists, monitoring DNS queries for the 104.18.40.47 address, and ensuring that email filtering rules block messages referencing the domain or related brand keywords. Given the Cloudflare front‑end, deeper investigation may require packet capture or request‑level analysis to confirm payload characteristics. Until additional evidence emerges, the prudent stance is to block all communications with uus-robinhood-apli.gitbook.io and continue monitoring threat‑intel feeds for any updates on its activity.