Vai al rapporto di sicurezza
⚠️
Questo dominio è stato segnalato come dannoso
Motori di sicurezza che segnalano un rilevamento: 17. Prestare estrema cautela: non inserire credenziali o informazioni personali.
REGISTRAR NEGLIGENCE · EGREGIOUS Sav.com, LLC was notified 4 months ago — the threat is still operational.
Why this matters — ICANN RAA §3.18 obligation & victim-assistance

On PhishDestroy delivered an evidence-backed abuse report (repeated 3 times, most recently ) to abuse@sav.com with the evidence stored for the case at that time. More than 4 months later, the phishing infrastructure remains reachable .

Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.

Victim-assistance obligation. If Sav.com, LLC doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 3 separate notifications over 4 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.

Elapsed since first report
4 months
Reports sent
3
Latest case ID
PD-1774621062-robux.media
Current status
Serving traffic (alive)
Sicurezza del dominio e intelligence sulle minacce

robux[.]media

Verifica phishing e sicurezza per robux.media

“Redeem Robux”

Verdetto di minaccia Critico Punteggio delle prove 100/100
Disponibilità Ultimo attivo conosciuto Ultima osservazione di raggiungibilità memorizzata
Segnali di rischio
Rilevamenti VirusTotal: 17/91 URLQuery threat systems: 5 alerts Simulazione del marchio: Robux Ultimo attivo conosciuto
17/91 VT URLQuery: 5 threat alerts OTX: 16 refs 24/11/2025 Robux Brand Impersonation 3 Reports Sent CDN
Riepilogo del rapporto

robux.media — Ultimo attivo conosciuto (HTTP 302). Simulazione del marchio: Robux; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VT 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); URLQuery 5 alerts; URLScan no malicious verdict; GSB no flag; BL 0; CF Radar malicious; PD 100/100. Registrar: Sav.com.

L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.

Riepilogo delle prove
CRITICO
Rif.
16C392E2
Punteggio
100/100
Modalità
Current evidence

PhishDestroy first observed robux.media on Nov 24, 2025. Positive findings were recorded by VirusTotal, Cloudflare Radar, and URLQuery. Evidence score: 100/100.

VirusTotal recorded 17 detections among 91 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data on Jul 26, 2026 at 02:58 UTC. Cloudflare Radar classified the domain as malicious; its source timestamp was not captured. URLQuery recorded 5 threat-system alerts on Apr 6, 2026 at 17:59 UTC. AlienVault OTX listed 16 community pulse references (not vendor detections) on Mar 1, 2026 at 16:41 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. Google Safe Browsing returned no flag on Mar 2, 2026 at 20:21 UTC. URLScan completed without a malicious verdict (score 0) on Feb 28, 2026 at 01:18 UTC. PhishStats returned no feed match on Mar 2, 2026 at 04:04 UTC.

HTTP 302 was recorded on Aug 7, 2026 at 10:24 UTC. Registration records list Sav.com, LLC as the registrar and Nov 2, 2025 as the registration date. At collection time, the domain resolved to 91.218.49.176. Collected metadata identifies Robux as the apparent target. Captured page title: “Redeem Robux”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Mar 11, 2026 at 09:22 UTC; stored DOM score 75/100. IoC extraction completed on Jul 29, 2026 at 02:42 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.

Stored full analysis07/07/2026

This site, robux.media, is an impersonation scam targeting users of the brand Robux. The page title "Redeem Robux" indicates it presents itself as a platform for redeeming in-game currency, posing a threat of credential theft or financial fraud by deceiving users into providing sensitive information.

Technical evidence shows the domain was flagged by 18 out of 95 VirusTotal vendors, including ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, and ESET. It is hosted on IP 91.218.49.176 in Ukraine (UA), under AS6698 Virtual Systems LLC. The domain was created on 2025-11-03, registered through Sav.com, LLC, and uses SSL certificates from Let's Encrypt (R12). Nameservers are logan.ns.cloudflare.com and cheryl.ns.cloudflare.com.

The site is currently down or offline. Its GridinSoft trust score is 1 out of 100, and it has a DOM risk score of 75, indicating a high risk level. It is also listed on 2 blocklists.

VirusTotal
VirusTotal
17 det.
URLQuery
URLQuery
5 threat alerts
OTX references
DNS Security
5/14
CF Radar
Malevolo
URLScan
URLScan
Gridinsoft
1/100
Certificato TLS
R12
Età
9 mo
Stato osservato
Ultimo attivo conosciuto 302
PhishDestroy
Elenco da eliminare
In elenco
Reports Sent
3 ignored
Copertura dei dati VirusTotal 17 / 91 URLQuery 5 threat-system alerts PhishStats checked — no match recorded OTX 16 community references CF Radar provider verdict: malicious URLScan capture rapporto memorizzato URLScan verdict Analisi completata Blocchi DNS 5/14 TLS valid certificate, 60d WHOIS 9 mo old Screenshot 3 captures · 3 sources Catena di reindirizzamenti non sondato Gridinsoft 1/100
Indicatori di sicurezza
GS Gridinsoft Analysis 1 / 100
Hosting SSL Certificate Phishing - High Risk Blacklisted by Security Providers Young Domain Blacklisted
Informazioni sulla sicurezza di rete
DNS Provider Blocks 5 / 14
Cloudflare Family Cloudflare Security Controld Adblock Controld Family Controld Malware
Threat Detection Systems 5 alerts
Detection System Indicator Verdict Alert
DNS4EU robux.media malicious Sinkholed
Cloudflare DNS robux.media malicious Sinkholed
DigiCert UltraDNS robux.media malicious Sinkholed
Hagezi Threat Feed robux.media malicious Sinkholed
DNS4EU taprain.com malicious Sinkholed
CF Cloudflare Radar Verdict Malevolo
Phishing Security threats Phishing

Pipeline di risposta alle minacce

Scoperta
Checks
Reports
Disponibilità
19/20
Initial Abuse Report (#1)
Sent to 1 abuse contact at Sav.com, LLC with forensic evidence
abuse@sav.com
27/03/2026
ICANN Escalation #2
Escalation #2 sent to 3 recipients including ICANN Compliance — follow-up record after a previous report
abuse@sav.comabuse@identitydigital.comcompliance@icann.org
06/04/2026
ICANN Escalation #3
Escalation #3 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@sav.comabuse@identitydigital.comcompliance@icann.org
17/04/2026
3 Reports Filed
3 report records were stored over 132 days; current observed status: Ultimo attivo conosciuto

Stato della lista di blocco pubblica

Acquisizione salvata

Titolo della pagina
Redeem Robux
Impersonates
Robux
Certificato TLS
Valid transport encryption · Emesso da R12 · valid for 60 days

Analisi dei domini

Dominio
URLScan Verdict Analisi completata score 0 report ↗
Server / ASN LiteSpeed · AS6698 virtualsystems Virtual Systems LLC, UA
IP Context CDN shared edge origin IP hidden La reputazione Edge-IP non è attribuita a questo dominio.
Indirizzo IP 91.218.49.176 CDN
PosizioneUA Kyiv, UA
ReteAS6698 · Virtual Systems LLC
L'IP di origine è nascosto dietro un proxy CDN. I risultati dell'IP inverso per l'indirizzo edge contengono tenant non correlati; la ricerca dell'origine richiede DNS passivo o dati di trasparenza del certificato.
RegistrazioneCreato 03/11/2025 (277d) Expires 03/11/2026
Stato HTTP302 Found (Temporary)
Elapsed Since First Report 111 days
Cosa conteggiamo Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Ultimo attivo conosciuto.
Minimum notice count 3 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Cosa contiene ogni rapporto I record archiviati dei report in uscita possono fare riferimento a prove disponibili in quel momento, come verdetti dei fornitori, dati di registrazione, dettagli di hosting, classificazioni o screenshot. Questa pagina non deduce l'esatto carico utile consegnato, la ricevuta, la conferma o l'azione da parte di un destinatario.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Dettagli tecniciDNS, SAN SSL, timestamp
Rilevato per la prima volta24/11/2025
DOM Analysisanalyzed 11/03/2026score 75/1001 brand signal
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://robux.media/
Nameserverlogan.ns.cloudflare.comcheryl.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 29/01/2026scanned 11/03/2026
Case ID
ICANN OVERSIGHT

Accreditamento e contesto RAA

ICANN ha incassato. La responsabilità non è arrivata.

Per questo gTLD, il registrar indicato sopra opera in base a un contratto con ICANN. ICANN riscuote tariffe annuali, variabili e basate sulle transazioni, legate a registrazioni, rinnovi e trasferimenti.

Accreditamento: monetizzato. Responsabilità: ricontrollare più tardi.

Poi inizia la magia: ICANN scrive il RAA §3.18, il registrar indaga sugli abusi all’interno della propria base clienti e le vittime forniscono gratuitamente le prove, mentre ogni livello aspetta che agisca qualcun altro. Se questo fa sentire le vittime più al sicuro, eccellente — la fattura ha funzionato.

Nota satirica sulla responsabilità Nulla viene inviato automaticamente.
Cronologia delle segnalazioni di abuso · 3 stored reports over 21 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
3 abuse reports filed over 132 days — latest observed status: Ultimo attivo conosciuto
The records name Sav.com, LLC as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
3
reports
132
days
ICANN CC
  1. Report #1 Mar 27, 2026 · 17:17 UTC
    Phishing Abuse Report: robux[.]media
    abuse@sav.com
  2. Report #2 ICANN CC 243h still active Apr 6, 2026 · 20:59 UTC
    ESCALATION #2 (243h active): Phishing - robux[.]media
    abuse@sav.com abuse@identitydigital.com compliance@icann.org
  3. Report #3 ICANN CC 492h still active Apr 17, 2026 · 05:58 UTC
    ESCALATION #3 (492h active): Phishing - robux[.]media
    abuse@sav.com abuse@identitydigital.com compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
Tecnologie · 3 identified
Tailwind CSS
UI frameworks

Utility-first CSS framework for rapid custom UI development.

LiteSpeed
Web servers

High-performance web server compatible with Apache configurations.

HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via Cloudflare Radar · Wappalyzer engine
Segnala questo dominio Invia le prove e contribuisci a proteggere gli altri

Analisi di VirusTotal

17 / I fornitori di sicurezza 91 hanno contrassegnato questo dominio
View on VT
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safe Browsing
Gridinsoft
Kaspersky
Lionic
SOCRadar
Sophos
VIPRE
Webroot
Yandex Safebrowsing

Prove archiviate

Wayback Machine Snapshot
È disponibile un'istantanea storica per la revisione delle prove
View Archive
Analisi delle prestazioni del sito

Google PageSpeed Insights — mobile performance audit of robux.media · checked Mar 1, 2026

99
Good
Performance
FCP
1.39s
First Contentful Paint
LCP
1.82s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.59s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Dati e relazioni esterne

Questo sito ti ha influenzato in qualche modo?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.

Europol
Trova il canale di segnalazione ufficiale per il tuo paese dell'UE
National police directory
Attenzione ai truffatori che promettono il recupero dei fondi! I criminali possono contattare nuovamente le vittime fingendo di essere investigatori, avvocati o agenti di recupero. Non pagare commissioni anticipate né condividere credenziali. Scopri di più sulle frodi relative ai sussidi di recupero →

Segnalalo alle autorità locali

Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.

Elenco di 97 paesi
Bozza assistita dall'intelligenza artificiale: i dettagli dell'incidente vengono elaborati dal fornitore di intelligenza artificiale Controllalo e invialo tu stesso

Informazioni su questo rapporto: robux.media

Questo rapporto presenta le ultime prove archiviate disponibili per PhishDestroy. I timestamp della sorgente vengono mostrati ove disponibili; la disponibilità e i verdetti del fornitore possono cambiare dopo il ritiro.

Il sito catturato mostrava il titolo della pagina “Redeem Robux” e potrebbe spacciarsi per Robux.

Al momento di 07/08/2026, robux.media ha ricevuto rilevamenti dai motori di sicurezza 17.

Se ritieni che questo elenco sia impreciso, presentare ricorso. Per conoscere la nostra metodologia, visita Pagina delle domande frequenti.

Verifica qualsiasi dominio

Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica

Scansiona ora

Segnala un tentativo di phishing

Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità

Segnala

Feed in tempo reale sulle minacce

Segnalazioni recenti di phishing e modifiche osservate della disponibilità

Monitora

Rimani informato, rimani al sicuro

Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo

Feed in tempo reale sulle minacce Contesta questo annuncio
HTML · IFRAME

Incorpora questo rapporto

Condividi queste informazioni sulle minacce sul tuo sito web o sul tuo blog

embed.html
<iframe
  src="https://phishdestroy.io/it/embed/domain/robux.media"
  title="PhishDestroy threat report for robux.media"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Una lettera di ringraziamento molto sincera

Generatore di bozze satiriche

Destinatario
Contesto delle tariffe

Bozza satirica. Gli importi delle tariffe sono stime; non si afferma che siano attribuibili esattamente a questo dominio.