# PhishDestroy threat dossier — v0-robloxi.vercel.app ================================================================ Fetched: 2026-07-22 06:27:13 UTC Canonical: https://phishdestroy.io/domain/v0-robloxi.vercel.app/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Airdrop Targeted brand: Roblox ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Yandex Safebrowsing Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 64.29.17.195 (US, Walnut) ASN: AS16509 Amazon.com, Inc. Hosting org: Vercel, Inc Registrar: Vercel Page title: RobuxFund - Claim Your Reward HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR1 Expires: 2026-09-26 Status: INVALID chain Fingerprint: ee54cb11f16cc311b3acbae57f8fbb03f338c1b2a20de72722c3eafd0dae0140 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 12:38:32 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 08:20:23 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-21 20:23:45 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] v0-robloxi.vercel.app Fake Roblox Airdrop Alert This domain, v0-robloxi.vercel.app, is currently active and classified as a high‑risk brand‑impersonation site targeting Roblox users. The site returns HTTP 200 and presents the page title “RobuxFund – Claim Your Reward,” which aligns with the declared scam type of a fake airdrop. Infrastructure analysis shows the domain is hosted on Vercel, resolves to the IP address 64.29.17.195, and the IP is geolocated to the United States under Vercel, Inc. The TLS certificate is issued by Google Trust Services (WR1) and the server enforces HSTS, indicating a legitimate‑looking HTTPS configuration despite the malicious intent. The domain was registered through Vercel’s platform, and the same provider is identified in the technology fingerprint. Detection services have flagged the domain: four of ninety‑one VirusTotal scanners reported it as malicious, and it appears on a single external blocklist. PhishDestroy has also listed the domain as blocked. No additional public threat‑intel feeds (e.g., OTX) or safe‑browsing checks were provided in the current data set. Because the site’s content has not been manually inspected, visual or functional details remain unverified. Defenders should immediately block DNS resolution for v0-robloxi.vercel.app, add the IP 64.29.17.195 to network‑level deny lists, and monitor outbound connections for attempts to contact the host. Security teams are advised to update web‑filter and email‑gateway signatures with the observed page title and SSL fingerprint to catch related phishing attempts. Continuous monitoring of Vercel‑hosted subdomains is recommended, as the platform can be leveraged for rapid deployment of similar impersonation campaigns. The high risk rating reflects the combination of brand targeting, active hosting, and multiple vendor detections, and the domain should be treated as a confirmed malicious indicator until further takedown confirmation. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: ee54cb11f16cc311b3acbae57f8fbb03f338c1b2a20de72722c3eafd0dae0140 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/v0-robloxi.vercel.app/ JSON API: https://api.destroy.tools/v1/check?domain=v0-robloxi.vercel.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,722 domains (57,299 alive under monitoring, 128,779 confirmed takedowns/dead). Site: https://phishdestroy.io