Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 2 times, most recently ) to restore2vuori@gmail.com with the evidence stored for the case at that time.
More than 5 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If ST Registry doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 2 separate notifications over 5 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
rbxmod[.]st
Проверка домена rbxmod.st на фишинг и безопасность
“RBXMOD - Premium Roblox Tools”
rbxmod.st: VirusTotal — 5 срабатываний из 91. Проверьте DNS, SSL, регистратора, блок-листы и данные об угрозах.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy first observed rbxmod.st on Mar 6, 2026. Evidence score: 80/100 (a triage score, not a probability).
Threat signals: 5 of 91 VirusTotal engines flagged the domain on Aug 5, 2026 at 14:30 UTC. Spamhaus DBL: DBL_SPAM on Jul 14, 2026 at 02:32 UTC.
The latest probe reached the domain (HTTP 200) on Aug 6, 2026 at 22:22 UTC. Reachability alone does not establish whether the content is safe.
Other observations: No external blocklist matches were recorded in the snapshot from Aug 6, 2026 at 22:20 UTC. Google Safe Browsing recorded no flag on Jun 26, 2026 at 15:16 UTC. AlienVault OTX recorded 0 community pulse references on Mar 6, 2026 at 08:55 UTC. A URLScan capture is available, but no capture timestamp was recorded. Negative or missing results do not establish safety.
Context: registrar ST Registry, IP address 151.247.193.142, registration date Mar 6, 2026, apparent target Roblox. Infrastructure details may have changed since collection.
This report summarizes time-bound observations, not a live guarantee. Avoid interacting with the domain; submit an appeal if the report is inaccurate.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
История жалоб на злоупотребления · 2 stored reports over 5 days · click to expand
-
Report #2 ICANN CC 652h still active Apr 2, 2026 · 17:48 UTCESCALATION #2 (652h active): Phishing - rbxmod[.]strestore2vuori@gmail.com abuse@nic.st compliance@icann.org
-
Report #3 ICANN CC 751h still active Apr 6, 2026 · 20:56 UTCESCALATION #3 (751h active): Phishing - rbxmod[.]strestore2vuori@gmail.com abuse@nic.st compliance@icann.org
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of rbxmod.st · checked Jun 26, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Об этом отчете: rbxmod.st
В этом отчете представлены последние сохраненные доказательства, доступные PhishDestroy. Временные метки источника отображаются там, где они доступны; Вердикты о доступности и поставщика могут измениться после сбора.
Захваченный сайт отображал заголовок страницы “RBXMOD - Premium Roblox Tools” и мог выдавать себя за Roblox.
Начиная с 07.08.2026, rbxmod.st обнаруживался механизмами безопасности 5.
Если вы считаете, что это объявление неточно, подать апелляцию. Чтобы узнать о нашей методологии, посетите Страница часто задаваемых вопросов.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание