Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 18. Exercise extreme caution — do not enter credentials or personal information.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@contabo.de. The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
1 month
Reports sent
1
Latest case ID
PD-20260714-D2E922
Current status
Observed active at latest stored check
Domain security and threat intelligence

htttps-www-roblox[.]co

“FASTPANEL”

Threat verdict Critical 95/100 evidence score
Availability Unverified Current reachability is unverified
VirusTotal detections: 18/91 URLQuery threat systems: 1 alert Brand impersonation: Roblox
Jul 14, 2026 Roblox 1 Report Sent
Evidence Summary
CRITICAL
Ref
7D11EFB4
Score
95/100

Analysis of the domain htttps-www-roblox.co shows a recently registered web address created on June 23, 2026 and currently active. The domain resolves to the IPv4 address 79.143.180.137 and is hosted under the DYNADOT LLC registrar. Its authoritative DNS configuration lists two Cloudflare nameservers, arushi.ns.cloudflare.com and arvind.ns.cloudflare.com, indicating use of a third‑party DNS service for resilience or concealment. VirusTotal scans have recorded detections by 7 of 91 security vendors, providing independent confirmation that the site exhibits characteristics associated with malicious activity. No additional technical artifacts, such as malware hashes or payload samples, have been disclosed, leaving the exact phishing vector and content unverified. Defenders should block network communications to the identified IP address, add the domain to URL filtering and threat intelligence feeds, and monitor for any related C2 traffic leveraging the same DNS providers. Continued observation of the domain’s DNS records and periodic re‑scanning are recommended to track changes in detection rates or infrastructure modifications.

VirusTotal
VirusTotal
18 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
TLS Certificate
FASTPANEL / parking
Age
2 mo New
Observed status
Unverified
PhishDestroy
DestroyList
Listed
Reports Sent
1
Data coverage VirusTotal 18 / 91 URLQuery 1 threat-system alert PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict Analysis completed DNS blocks not checked TLS valid certificate, 281d WHOIS 2 mo old Screenshot 3 captures · 3 sources Redirect chain not probed
Network Security Intelligence
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU htttps-www-roblox.co malicious Sinkholed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
11/12
Sent Report Recorded
Stored sent-report record for registrar DYNADOT LLC, hosting provider, 2 abuse contacts
abuse@contabo.deabuse@dynadot.com
Jul 14, 2026

Public Blocklist Status

Stored Capture

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN nginx/1.30.2 · AS51167 Contabo GmbH
IP Reputation abuse score 0/100 0 reports checked Aug 14, 2026
IP Address 79.143.180.137 FR
GeoFR Lauterbourg, FR
NetworkAS51167 · Contabo GmbH
RegistrationCreated Jun 23, 2026 (55d · New) Expires Jun 23, 2027
Technical detailsDNS, SSL SANs, timestamps
First DetectedJul 14, 2026
DOM Analysisanalyzed Jul 14, 2026score 78/100
IoC Extractionscanned Jul 29, 20260 wallet · 0 Telegram IoCs
Submitted URLhttp://htttps-www-roblox.co/users/05754151/profile
Nameserversarushi.ns.cloudflare.comarvind.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from May 25, 2026scanned Jul 14, 2026
Case ID
Page Title
FASTPANEL
TLS Certificate
Valid transport encryption · Issued by FASTPANEL / parking · valid for 281 days
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

18 / 91 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 9 detections
Criminal IP
alphaMountain.ai
BitDefender
Cluster25
CRDF
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
LevelBlue
Lionic
MalwareURL
SOCRadar
Sophos
VIPRE
Webroot
Yandex Safebrowsing

Evidence & External Reports

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260714-D2E922 Recipient: abuse@contabo.de
Page title stored with report: FASTPANEL
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 142.8 KB

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/htttps-www-roblox.co"
  title="PhishDestroy threat report for htttps-www-roblox.co"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>