# PhishDestroy threat dossier — roblodx.com ================================================================ Fetched: 2026-06-20 15:20:56 UTC Canonical: https://phishdestroy.io/domain/roblodx.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 18/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Emsisoft, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, MalwareURL, Netcraft, SOCRadar, Sophos, VIPRE, Webroot AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 38.97.40.99 (US, Clifton) Hosting org: AS174 Cogent Communications, LLC Registrar: IONOS SE Nameservers: ["ns1.ultahost.com", "ns2.ultahost.com", "ns3.ultahost.com", "ns4.ultahost.com"] Registered: 2025-07-19 Expires: 2026-07-19 Page title: FrostByte - Home HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-24 Status: INVALID chain Fingerprint: 2f4097b432a8b612d2b44860f214787fb2f5f0c0fe9e81f9f0e87b2285b78e39 Subject Alternative Names (related infrastructure — often same operator): - autodiscover.roblodx.com - cpanel.roblodx.com - cpcalendars.roblodx.com - cpcontacts.roblodx.com - webdisk.roblodx.com - webmail.roblodx.com - www.roblodx.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-07-19 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-09 12:16:02 UTC (by PhishDestroy tracker) First reported: 2026-06-09 12:13:45 UTC (abuse notice filed) Last verified: 2026-06-20 16:20:35 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-09 12:16:27 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies roblodx.com as an active crypto drainer domain engaged in a suspected cryptocurrency theft campaign. The domain mimics Roblox branding and utilizes social engineering tactics to trick users into connecting fraudulent wallet drainer kits. Security researchers have flagged this domain due to its rapid proliferation across phishing campaigns targeting gaming and Web3 user communities. The site is currently under forensic analysis to determine the specific drainer kit implementation and distribution vectors, as no publicly documented exploit payload has been fully reverse-engineered at this time. This domain resolves to IP address 38.97.40.99 and operates with a valid Let’s Encrypt SSL certificate (likely used to increase trust in phishing lures). As of the latest scan, roblodx.com has 0 detections on VirusTotal out of 95 engines, indicating it remains under the radar of mainstream antivirus systems. The domain was registered recently and has been assigned to an unknown entity; however, the registrar and creation date are not publicly disclosed in the current intelligence feed. It is currently blocked by one major blocklist—OISD—and remains unindexed by Google Safe Browsing (GSB status: under_investigation). This combination of a low detection rate, SSL certificate usage, and targeted mimicry suggests a coordinated, evolving threat with potential to evade detection. PhishDestroy continues to monitor roblodx.com under active investigation status, with real-time tracking of its domain behavior and IP associations. The current risk level is classified as under_investigation due to the lack of conventional malware signatures, but behavioral patterns and brand impersonation strongly indicate malicious intent. Users are advised to avoid interacting with this domain, especially in the context of cryptocurrency transactions or login prompts. If you have recently visited this site, disconnect your wallet immediately and perform a comprehensive security audit. To verify domain safety and stay informed about emerging threats, always check against PhishDestroy’s live database. While the immediate risk remains unconfirmed, this domain represents a serious and escalating threat vector that warrants heightened user awareness and caution. [Updates since narrative was generated:] - WHOIS creation date: 2025-07-19 ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 5f60c590da55c91dcee94ce4011e3888 TLS cert SHA-256: 2f4097b432a8b612d2b44860f214787fb2f5f0c0fe9e81f9f0e87b2285b78e39 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/roblodx.com/ JSON API: https://api.destroy.tools/v1/check?domain=roblodx.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 166,763 domains (13,153 alive under monitoring, 153,292 confirmed takedowns/dead). Site: https://phishdestroy.io