DomainMediumSignal 75/100
roblox.com.py
Location
First Seen
Apr 19, 2024
Last Seen
Jun 7, 2026
Found in 19 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
75%
Signal Score
75 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
19 reports75% confidence
19
Source reports
75%
Confidence score
Category tags
#supportsitewebsiteabuse #rootcertificatefailure #cryptographicfa16z-cryptoa16z-impersonationaccess controlaccommodation and food servicesaccommodation servicesaccount discoveryaccount profilingaccount takeoveraccount-abuseaccount-creation-abuseaccount-verification-abuseactiveactive phishing campaignactive scanactive scanningactive-threatsactivecampaign-impersonationaggressive-redirectanonymous-account-creationanonymous-registrationapple security bypassas path poisoningattachment exploitationattackattack_vector: social_engineeringauthentication attacksautomated-scanautomated-threat-intelligenceautomotive manufacturingbad reputationbecbgpbloat-ablocklistbooking-com-impersonationbotnetbotnet activitybrand impersonationbrand-abusebrand-impersonationbrute forceburn-and-turnbusiness email compromisecardingcartao-continentecash-app-impersonationcertcertificate spoofingcivil servicescloakingcloud-flarecommand and controlcommunication technologiescommunity-sourcedcompromised infrastructurecontentcore network compromisecredential accesscredential harvestingcredential stuffingcredential theftcredential theft attemptcredential-harvestingcredential-theftcryptocrypto-casino-scamcrypto-phishingcrypto-scamcrypto-walletcryptocurrencycryptocurrency threatscryptocurrency-fraudcryptocurrency-scamcryptocurrency-scamscryptojackingcyber threatscymtdaily-threat-inteldata exfiltrationdata interceptiondata store exposuredata-theftdating-scamddosddos attacksdeceptive contentdeceptive redirectsdeceptive-domaindeceptive-interfacedeceptive-redirectdeceptive-redirectsdeceptive-tacticsdelivery_method: emaildestroylist_phishingdiscorddisposable-domaindisposable-infrastructuredistributed attacksdmca-takedowndomain-blocklistdomain-classificationdomain-iocdomain-rotationdomain-squattingdraineredge infrastructure exploitelectronics manufacturingemail-credentialsemail-login-impersonationenumerationesports-targetingeuropeevasionevasion-tacticexecutable fileexplicit-lureexploitation activityfake-account-creationfake-errorfake-loginfake-online-storesfake-order-confirmationfake-verificationfake-voting-contestfilefinancefinancial servicesfinancial-fraudfinancial-information-theftfinancial-scamfinancial-service-impersonationfirmware attackflorida-dmvfood servicesform submissionform submission phishingfraudfraud-enablerfraud-enablingfraudulent-activityfraudulent-gamblinggambling-scamgame designgame developmentgame publishinggaminggaming industrygaming platformsgaming technologygeofencing malwaregermanygibberish-domaingoogle-docs-scamgoogle-formsgoogle-meet-impersonationgovernment technologyguest serviceshacking-toolhigh-risk-tldhospitality technologyhotelsidentity & access exploitationidentity-theftidmsa abuseillegal-marketplaceimpossible-metricsindicatorindicator-of-compromiseindicators of compromiseindustrial automationindustrial iotindustrial productioninformation technologyinitial accessinjection activityinstagram-impersonationinter-as route manipulationinternet of thingsinvestment-fraudinvestment-scamiocsiot botnetiot securityiot/ics attackit infrastructureitem-opening-scamjtag exploitationlarge-scale-operationlarge-scale-schemelateral network movementlink injectionlink manipulationliveloyalty-program-scammalicious activitymalicious attachmentmalicious domainmalicious domain disseminationmalicious emailmalicious filemalicious linkmalicious linksmalicious softwaremalicious urlsmalicious-link-distributionmalicious-platformmalicious-redirectmalicious-redirectionmalicious-redirectsmalicious-url-feedmalvertisingmalwaremalware deliverymalware distributionmalware hostingmalware-distributionmalware-droppermanufacturing technologymedia / entertainmentmirai botnetmobile carriersmobile gamingmobile networksmobile-ui-scamnebula-xnemucodnetworknetwork infrastructure attacknetwork reconnaissancenetwork scanningnew-domainnewly-registered-domainoauth-credential-harvestingonline-gamblingpay-for-datespayment-information-harvestingpdfpersistence mechanismphishphishingphishing attackphishing campaign detectedphishing campaign detectionphishing domain listphishing domainsphishing urlphishing-databasephishing-websitesphishing_type: spearphishingpii-harvestingpmic manipulationpolandpolcertprivacy-evasionprocess injectionprocess manufacturingprotocol-devipublic administrationpublic infrastructurepublic policypupqr-code-phishingquality controlransomwarereconnaissancerecruitment-scamredirect-chainredirect-cloakingregulatory agenciesresearchedresource hijackingrestaurant operationsretail / e-commerceretail-fraudrobloxroblox-impersonationromaniarouting protocolscamscam-templatescamsscams & fraudsecurity operationssecurity policyseychellessms-verification-bypasssocial engineeringsocial engineering attacksocial-media-scamsocial-media-scamssoftware developmentsophisticated firmware persistencespearphishingspoofing_technique: domain_spoofingspoofing_technique: email_spoofingsteamsupply chain attacksupply chain compromisesupply chain managementsuspicious-domainsuspicious-tldt1021t1055t1059t1059.004t1071t1071.001t1071.004t1078t1078.004t1105t1110t1113t1189t1190t1192t1199t1204t1204.001t1204.002t1486t1496t1499.001t1499.002t1499.003t1534t1539t1542.001t1542.005t1550t1552t1552.001t1564.001t1565t1566t1566.001t1566.002t1566.003t1566.004t1567t1567.001t1571t1583.001t1588t1588.002t1595t1595.001t1595.002t1595.003t1598t1598.003targeted-phishingtargeting databasetech-support-scamstelecom servicestelecommunicationstelecommunications-phishingtemporary-phone-numbertemporary-phone-numbersthreat actorthreat indicatorsthreat intelligencethreat intelligence feedthreat preventionthreat-feedthreat-intelligencethreat_objective: credential_theftthreat_objective: malware_deliverythrowaway-domaintier-1 network vulnerabilitytld-squattingtor nodetourismtracking-urltradeville-impersonationtravel-booking-scamtravel-scamtyposquattingunited statesurl-based phishingurl-blockingurl-iocurl-obscurityurl-redirectionurl-shortenerurlertusdt-scamverification-bypassverified-threatsvideo gamesvulnerability scanw32.bloat-awallet-drainerwallet-drainingwallet-theftweb hostingweb securitywebsite impersonationwhaling attackxvideosyoutube-botsyoutube-impersonation
Activity Timeline
Jun 7Jun 7
Threat Activity Heatmap
· Peak: 2026-06-07LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated
The domain **roblox.com.py** has emerged as a significant indicator of compromise (IOC) associated with multiple cyber threats, including botnets, malware, phishing, and ransomware. First observed on April
Threat ScoreHigh Risk
75
SIGNAL
Signal Score
75%
Confidence
19
Reports
First seenApr 19, 2024
Last seenJun 7, 2026
VirusTotal
Not checked
WHOIS
- description
- LTNA Cyber provides additional enrichment for domain and URL indicators, including RIR and DNS intelligence, domain registration context, routing verification, BGP stream visibility, and GeoIP/ISP attribution. Learn more: https://ltna.com.au/cyber
- domain rank
- -1
- references
- Conversely, Port 443 remains accessible, serving a WordPress-based interface backed by a freshly issued Google Trust Services certificate (Feb 4, 2026). This asymmetric configuration ensures that the structurally invalid X.509 "Broken Seal" is only delivered via encrypted channels, while the gated Port 80 tier prevents the discovery of the underlying Zeppelin/Bloat-A redirection logic by non-human-interacted sessions., Imphash: 9698f46495ce9401c8bcaf9a2afe1598 | Imports (additional): GdipSetSmoothingMode, I_UuidCreate, RpcStringFreeW, UuidCreate, UuidToStringW, InternetCheckConnectionW | Resource: RT_MANIFEST (1, ENGLISH US, SHA-256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df, XML, entropy 4.91), Observed hosting and routing telemetry indicates the delivery infrastructure is operating through AS209242 (Cloudflare London LLC), suggesting the actor is leveraging Cloudflare’s transit layer for resilience and to reduce direct exposure of origin infrastructure., Research into the gogetlife.co telemetry confirms a dual-port obfuscation strategy designed to bypass multi-layer security indexing. Forensic HTTP scans identify a Port 80 "Fail-Closed" state, where standard web traffic is gated by a Cloudflare-managed 403 Forbidden challenge, effectively neutralizing automated crawlers. Conversely, Port 443 remains accessible, serving a WordPress-based interface backed by a freshly issued Google Trust Services certificate (Feb 4, 2026). This asymmetric configuration ensure, Compilation / Toolchain Compiler: Microsoft Visual C++ 2017 Linker: Microsoft Linker 14.16.27032 IDE: Visual Studio 2017 (15.9) Classification: PEBIN TrID: Win64 EXE (32.2%) / Win32 DLL (20.1%) / Win16 NE (15.4%) PE Section Entropy (Suspicion): .data 7.36 → high (suggests packing/encryption), .reloc 6.66 → possible runtime modification, .text 6.01, .rdata 5.88, .rsrc 4.72 Imports (Capabilities): CreateRemoteThread, CreateThread, ExitProcess, Broken Seal exploitation: The invalid X.509 seal appears engineered to exploit verification logic gaps, forcing fail-open behavior and allowing SEG bypass under certain configurations. Human-gated delivery posture: Cloudflare 403 challenges suggest the actor enforces human interaction before payload delivery, reducing automated discovery and sandbox analysis. Industrialized infrastructure: Correlation across thousands of domains and URLs indicates a highly automated, rotating delivery ecosystem., MITRE ATT&CK: Process Hollowing (T1055.012): Documentation on the RunPE injection method used by the payload to achieve a fileless state in RWX memory. RFC 5652 - Cryptographic Message Syntax (CMS): This standard defines the structure of the digital signatures that this campaign's "Broken Seal" exploit bypasses., As of Feb 13 (early AM) — Indicators of Compromise: 17K | Types: Email (30), FileHash-SHA256 (2,146), URL (8,070), Hostname (2,755), Domain (3,528), Other (1,110) | Geo: US (233), Canada (15), China (10), Japan (2), Spain (2), Other (13), Verification failure observed in automated verification handlers during sandbox replay., The payload (SHA256: dfff54...4af) achieves a fileless execution state via Process Hollowing (RunPE), injecting into RWX memory regions of legitimate system processes to evade disk-based EDR telemetry. Anti-analysis controls—including Bochs artifact checks, geofencing logic, and direct CPU clock interrogation—are implemented to validate a high-interaction user environment prior to execution., Multiple antivirus engines flagged the sample with generic heuristic names (e.g., Trojan:Win32/Vigorf.A, Win32:Malware-gen, Trojan.Generic), consistent with multi-engine heuristic detection on VirusTotal., Malicious sample (SHA256: fa8e2ddfe42e77a9771a7c4d6421c7a808cf4508f8cd6dc6f4cf8bd4e2ae7f8f) detected as TrojanDownloader:Win32/Tugspay.A with YARA hits for Win32_PUA_Domaiq, aPLib, PECompact_2xx and IDS alerts including TLS Handshake Failure + 403 Forbidden, contacting 36 domains (e.g., api.123mediaplayer.com, static.sslsecure1.com) and IPs such as 104.18.23.19 and 193.166.255.171., SHA256 3d10374b55a18a2dd90d35d28472600496c680a7efab4e772595f735cb062343 identified as Win.Malware.Vtflooder-9783271-0 / Trojan:Win32/Vflooder.B with UPX/Nrv2x packing YARA hits, IDS detections for Win32/Vflooder.B check-in and DOS behavior, and network C2 indicators including 172.66.0.227 and 34.54.88.138., SHA-256: fc1fedce1419d4e2009828aad8644deca78b4eeed176e5b009797e0eb0d7d3ff — Detected as Win.Malware.Vtflooder / Trojan:Win32/Vflooder; UPX-packed PE32 executable, with 812 IDS hits (including C2 checkin + HTTP EXE upload)., nationalgrid.com — Whitelisted domain (US, AS13335 Cloudflare) with 500+ passive DNS entries, 692 URLs, 195 subdomains, and 2 malicious files hosted on IP 104.17.1.192, which is concerning given the infrastructure and trust level., eversource.com (IP: 159.108.5.46, ASN: AS2024) has 2 flagged malicious files within its infrastructure, despite being whitelisted. The domain hosts 95 subdomains and maintains an active SPF record, indicating potential security risks under an otherwise trusted facade., Whitelisted IP Address 204.79.197.212 Location United States ASN AS8068 microsoft corporation Nameservers ns4-205.azure-dns.info. , ns1-205.azure-dns.com. More WHOIS Registrar: MarkMonitor, Inc., Creation Date: Mar 26, 1996 Related Pulses OTX User-Created Pulses (50) Related Tags 2025 Related Tags 4328 , 5943 , 80211 , #supportsitewebsiteabuse #rootcertificatefailure #cryptographicf , The dynamics of the mudoSOSIntersectalign with sophisticated adv More Indicator Facts 982 malicious files communicat, The AlienVault OTX report for flypdx.com documents 11 related tags, including ids detections and av detections, across 4 active AWS IP addresses (3.175.34.30–.106). These indicators confirm the airport's network has been flagged for unauthorized activity, specifically pointing to a bridge between their web infrastructure and internal passenger tracking. The display of PII on aviation hardware during my June flight matches a known data-bleeding pattern where Personally Identifiable Information (PII) leaks fr, My Independent research finds an intersect between different pdf DV versions being able to connect to Raspberry Pi devices as it was the FCC application document. Risk: Mac ID connectivity to all., https://ltna.com.au/cyber, https://urlert.com/domain/acemlna.com, https://urlert.com/domain/adultpoint.info, https://urlert.com/domain/amplifyapp.com, https://urlert.com/domain/be-dmca.report, https://urlert.com/domain/beehiiv.com, https://urlert.com/domain/bit.ly, https://urlert.com/domain/bookingil.com, https://urlert.com/domain/cartaooocontinenteie.cyou, https://urlert.com/domain/ckq.cc, https://urlert.com/domain/cpanel.site, https://urlert.com/domain/crashradar.info, https://urlert.com/domain/creditscoreusa.org, https://urlert.com/domain/ct.ws, https://urlert.com/domain/cuesax.com, https://urlert.com/domain/cxr.cc, https://urlert.com/domain/drivehub.cfd, https://urlert.com/domain/effectivegatecpm.com, https://urlert.com/domain/eph.cc, https://urlert.com/domain/eu.cc, https://urlert.com/domain/expdepyapmentse.com
- subdomains count
- 23
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 2 years ago · Last seen 5 days ago
Appeared in 19 threat reports