rbxtools[.]st
Verificação de phishing e segurança de rbxtools.st
“rbxtools.st”
rbxtools.st — Último ativo conhecido (HTTP 200). Tipo de golpe: Gaming Scam. Resumo das evidências: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CyRadar); URLQuery 2 alerts; Spamhaus DBL_SPAM; PhishDestroy score 100/100. Registrador: ST Registry.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain was registered through the ST Registry on March 06, 2026 and resolved to IP 151.247.193.142, which is advertised as belonging to AS399486 (12651980 Canada Inc.) and geolocated in France. The authoritative nameservers ns1.eggywall.cc and ns2.eggywall.cc were observed at the time of resolution. An HTTPS service presented a valid Let’s Encrypt certificate (issuer E8) and responded with HTTP status 200, delivering a page whose title is exactly “rbxtools.st”. No additional content analysis is available.
The site was classified as a gaming‑related scam; it appeared on a single external blocklist and was subsequently blocked by the PhishDestroy service. Reputation scoring from Gridinsoft assigned a trust score of 1 out of 100. VirusTotal scans reported 16 detections out of 94 submitted security vendors, indicating a moderate level of consensus among scanners. The domain is currently taken offline, which limits real‑time observation but does not remove the historical indicators.
Defenders should continue to enforce outbound filtering for the resolved IP address, update internal blocklists with the domain and its associated nameservers, and monitor for any reuse of the hosting infrastructure. Because the site employed a legitimate TLS certificate, reliance on certificate validity alone is insufficient; detection logic should incorporate the observed HTTP response, low trust score, and the specific malware‑vendor detection count. Further investigation is recommended to determine whether the underlying server is being repurposed for additional phishing campaigns, and to verify that any credential‑stealing forms previously hosted are no longer reachable.
Sinais de segurança
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | rbxtools.st |
malicious | Sinkholed |
| DNS4EU | rbxtools.st |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo