robuxsupply[.]shop
“Claim Your Robux”
Zusammenfassung der Beweislage
This domain, robuxsupply.shop, is flagged as a confirmed brand impersonation site specifically targeting PayPal users through deceptive web pages. Analysis indicates the site presents a fraudulent interface titled 'Claim Your Robux,' designed to mimic legitimate reward or payment portals. The objective appears to be credential theft, where victims are tricked into entering sensitive account details under the pretense of claiming fictitious rewards, which are then harvested by threat actors for financial fraud or unauthorized account access.
Infrastructure analysis reveals the domain was registered on February 21, 2026, and resolves to the IP address 192.64.117.221, hosted under AS22612 (Namecheap, Inc.) in the United States. The domain lacks an SSL certificate, increasing the risk of data interception during transmission. Detection metrics confirm elevated malicious activity, with 13 out of 95 security vendors on VirusTotal flagging the domain as malicious. Additionally, the domain appears on one security blocklist, further corroborating its fraudulent nature. The registrar details and hosting provider align with patterns observed in other brand impersonation campaigns, suggesting potential reuse of infrastructure across multiple phishing operations.
Users who visited robuxsupply.shop or interacted with its content should immediately take corrective action. If credentials or financial details were entered, affected individuals must change their PayPal passwords and enable multi-factor authentication without delay. Monitoring for unauthorized transactions or account activity is critical, and any suspicious logins should be reported to the legitimate service provider. Browser caches and saved passwords associated with the domain should be cleared to prevent persistent exposure. Given the elevated risk level, users are advised to remain vigilant for follow-up phishing attempts via email or messaging platforms, as threat actors may attempt to exploit compromised information for further attacks.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt