# PhishDestroy threat dossier — python.irobot.com ================================================================ Fetched: 2026-07-29 00:13:10 UTC Canonical: https://phishdestroy.io/domain/python.irobot.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 45/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 199.36.158.100 (US, Mountain View) ASN: AS54113 Fastly, Inc. Hosting org: Google LLC Registrar: CSC Corporate Domains, Inc. Nameservers: ["udns1.cscdns.net", "udns2.cscdns.uk"] Page title: iRobot Education - Python Web Playground HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR3 Expires: 2026-10-22 Status: INVALID chain Fingerprint: 4f5652cea6bc436ea469f8f3116c327d432765c98c5d545802132d8d2eb9321d Subject Alternative Names (related infrastructure — often same operator): - ac4b18.score.se - admin.forallcommunity.com - agentathon.gdghyd.in - akshikacarecentre.co.in - alexsaidani.com - alorawilson.net - alunideas.com - api.prep.deliversense.com - app.butterflyit.com - app.whiteboard.church - bagavathimess.com - bmtegypt.com - chartoy.com - chat.av-pro.co.il - company.de.wowworks.org ... +84 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 22:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 00:20:27 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 22:24:10 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] python.irobot.com Generic Phishing Alert On 27 July 2026, python.irobot.com was identified as an active generic phishing infrastructure. The domain is registered through CSC Corporate Domains, Inc. and resolves to the authoritative name servers udns1.cscdns.net and udns2.cscdns.uk. HTTP requests to the host return a 200 OK status, indicating that a web service is currently reachable. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy feed, confirming that at least one reputable anti‑phishing source has flagged the site. VirusTotal records show that the domain has been scanned by 91 vendor engines, none of which have raised a detection at the time of analysis; the lack of detections is explicitly noted as insufficient evidence of legitimacy. No additional intelligence such as Safe Browsing, Open Threat Exchange, SSL certificate details, or IP/ASN information is available in the current dataset. Likewise, the page title, target brand, or any malicious payload characteristics have not been disclosed, leaving the exact content and victim‑targeting strategy unverified. Given the active status, reachable web service, and inclusion on a known blocklist, defenders should continue to treat python.irobot.com as a high‑confidence phishing indicator. Recommended mitigation steps include adding the domain to network‑level deny lists, enforcing URL filtering on corporate web gateways, and monitoring for any future detections in sandbox or endpoint telemetry. Periodic re‑scans on VirusTotal and other multi‑engine platforms are advised to capture any changes in detection status. Analysts should also seek to retrieve the landing page content to determine whether a specific brand is being spoofed, which would enable more precise threat‑intel sharing. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: fc9cded34ae965362a256f5ecc940387 TLS cert SHA-256: 4f5652cea6bc436ea469f8f3116c327d432765c98c5d545802132d8d2eb9321d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/python.irobot.com/ JSON API: https://api.destroy.tools/v1/check?domain=python.irobot.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,142 domains (83,029 alive under monitoring, 124,082 confirmed takedowns/dead). Site: https://phishdestroy.io