Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 3 times, most recently ) to abuse@sav.com with the evidence stored for the case at that time.
More than 4 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If Sav.com, LLC doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 3 separate notifications over 4 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
robux[.]media
Verifica phishing e sicurezza per robux.media
“Redeem Robux”
robux.media — Ultimo attivo conosciuto (HTTP 302). Simulazione del marchio: Robux; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VT 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); URLQuery 5 alerts; URLScan no malicious verdict; GSB no flag; BL 0; CF Radar malicious; PD 100/100. Registrar: Sav.com.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy first observed robux.media on Nov 24, 2025. Positive findings were recorded by VirusTotal, Cloudflare Radar, and URLQuery. Evidence score: 100/100.
VirusTotal recorded 17 detections among 91 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data on Jul 26, 2026 at 02:58 UTC. Cloudflare Radar classified the domain as malicious; its source timestamp was not captured. URLQuery recorded 5 threat-system alerts on Apr 6, 2026 at 17:59 UTC. AlienVault OTX listed 16 community pulse references (not vendor detections) on Mar 1, 2026 at 16:41 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. Google Safe Browsing returned no flag on Mar 2, 2026 at 20:21 UTC. URLScan completed without a malicious verdict (score 0) on Feb 28, 2026 at 01:18 UTC. PhishStats returned no feed match on Mar 2, 2026 at 04:04 UTC.
HTTP 302 was recorded on Aug 7, 2026 at 10:24 UTC. Registration records list Sav.com, LLC as the registrar and Nov 2, 2025 as the registration date. At collection time, the domain resolved to 91.218.49.176. Collected metadata identifies Robux as the apparent target. Captured page title: “Redeem Robux”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Mar 11, 2026 at 09:22 UTC; stored DOM score 75/100. IoC extraction completed on Jul 29, 2026 at 02:42 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis07/07/2026
This site, robux.media, is an impersonation scam targeting users of the brand Robux. The page title "Redeem Robux" indicates it presents itself as a platform for redeeming in-game currency, posing a threat of credential theft or financial fraud by deceiving users into providing sensitive information.
Technical evidence shows the domain was flagged by 18 out of 95 VirusTotal vendors, including ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, and ESET. It is hosted on IP 91.218.49.176 in Ukraine (UA), under AS6698 Virtual Systems LLC. The domain was created on 2025-11-03, registered through Sav.com, LLC, and uses SSL certificates from Let's Encrypt (R12). Nameservers are logan.ns.cloudflare.com and cheryl.ns.cloudflare.com.
The site is currently down or offline. Its GridinSoft trust score is 1 out of 100, and it has a DOM risk score of 75, indicating a high risk level. It is also listed on 2 blocklists.
Indicatori di sicurezza
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | robux.media |
malicious | Sinkholed |
| Cloudflare DNS | robux.media |
malicious | Sinkholed |
| DigiCert UltraDNS | robux.media |
malicious | Sinkholed |
| Hagezi Threat Feed | robux.media |
malicious | Sinkholed |
| DNS4EU | taprain.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
ICANN ha incassato. La responsabilità non è arrivata.
Per questo gTLD, il registrar indicato sopra opera in base a un contratto con ICANN. ICANN riscuote tariffe annuali, variabili e basate sulle transazioni, legate a registrazioni, rinnovi e trasferimenti.
Accreditamento: monetizzato. Responsabilità: ricontrollare più tardi.
Poi inizia la magia: ICANN scrive il RAA §3.18, il registrar indaga sugli abusi all’interno della propria base clienti e le vittime forniscono gratuitamente le prove, mentre ogni livello aspetta che agisca qualcun altro. Se questo fa sentire le vittime più al sicuro, eccellente — la fattura ha funzionato.
Cronologia delle segnalazioni di abuso · 3 stored reports over 21 days · click to expand
-
Report #1 Mar 27, 2026 · 17:17 UTCPhishing Abuse Report: robux[.]mediaabuse@sav.com
-
Report #2 ICANN CC 243h still active Apr 6, 2026 · 20:59 UTCESCALATION #2 (243h active): Phishing - robux[.]mediaabuse@sav.com abuse@identitydigital.com compliance@icann.org
-
Report #3 ICANN CC 492h still active Apr 17, 2026 · 05:58 UTCESCALATION #3 (492h active): Phishing - robux[.]mediaabuse@sav.com abuse@identitydigital.com compliance@icann.org
Tecnologie · 3 identified
Utility-first CSS framework for rapid custom UI development.
High-performance web server compatible with Apache configurations.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of robux.media · checked Mar 1, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Informazioni su questo rapporto: robux.media
Questo rapporto presenta le ultime prove archiviate disponibili per PhishDestroy. I timestamp della sorgente vengono mostrati ove disponibili; la disponibilità e i verdetti del fornitore possono cambiare dopo il ritiro.
Il sito catturato mostrava il titolo della pagina “Redeem Robux” e potrebbe spacciarsi per Robux.
Al momento di 07/08/2026, robux.media ha ricevuto rilevamenti dai motori di sicurezza 17.
Se ritieni che questo elenco sia impreciso, presentare ricorso. Per conoscere la nostra metodologia, visita Pagina delle domande frequenti.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo