Skip to security report
Domain security and threat intelligence
roblox-canjear.online favicon

roblox-canjear.online

“Roblox”

Threat verdict Critical 100/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
VirusTotal detections: 18/89 URLQuery threat systems: 5 alerts Brand impersonation: Roblox
May 7, 2026 Roblox 1 Report Sent
Actions API
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 18. Exercise extreme caution — do not enter credentials or personal information.

Evidence Summary

CRITICAL
Score
100/100

This domain, roblox-canjear.online, operates as a credential theft site specifically targeting users of the Roblox gaming platform. Analysis of the page structure and metadata reveals an attempt to impersonate the legitimate Roblox login interface, likely designed to harvest user credentials through deceptive input forms. The inclusion of reCAPTCHA technology suggests an effort to appear legitimate while evading automated detection systems, a common tactic in credential harvesting campaigns targeting gaming communities. Infrastructure analysis provides multiple indicators of malicious intent. The domain was registered on August 30, 2025, through Dattatec Corp, with an unusually short lifespan typical of phishing operations. It resolves to the IP address 200.58.111.123 and is currently flagged by 24 out of 95 security vendors on VirusTotal. The domain appears on four distinct security blocklists, including PhishDestroy and PhishingArmy, and maintains a Gridinsoft trust score of 0/100 alongside an 8/100 Scamadviser rating. Google Safe Browsing has classified this as social engineering content, further confirming its malicious nature. Users who visited roblox-canjear.online should immediately perform several security measures. Any credentials entered on the site must be changed from a secure device, with priority given to Roblox accounts and any platforms where password reuse occurred. Multi-factor authentication should be enabled on all critical accounts to prevent unauthorized access. System scans using updated security tools are recommended to detect potential secondary infections. Users should monitor financial accounts and gaming inventories for unauthorized transactions or item transfers, as credential theft often precedes account takeovers and virtual asset theft.

VirusTotal
VirusTotal
18 det.
URLQuery
URLQuery
5 threat alerts
DNS Security
6/14
CF Radar
Malicious
URLScan
URLScan
ScamAdviser
Scamadviser
8/100Very Likely Unsafe
TLS Certificate
Let's Encrypt 27d
Age
1 yr
Observed status
Content unavailable
PhishDestroy
DestroyList
Listed
Reports Sent
1
Data coverage VirusTotal 18 / 89 URLQuery 5 threat-system alerts PhishStats checked — no match recorded OTX no community references CF Radar provider verdict: malicious URLScan capture stored report URLScan verdict Analysis completed DNS blocks 6/14 TLS valid certificate, 27d WHOIS 13 mo old Screenshot 3 captures · 3 sources Scamadviser 8/100
Network Security Intelligence
DNS Provider Blocks 6 / 14
Brand Roblox Cloudflare Family Cloudflare Security Controld Adblock Controld Family Controld Malware
Threat Detection Systems 5 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS roblox-canjear.online malicious Sinkholed
OpenDNS roblox-canjear.online phishing Phishing Block
DigiCert UltraDNS roblox-canjear.online malicious Sinkholed
Hagezi Threat Feed roblox-canjear.online malicious Sinkholed
CIRA Canadian Shield DNS roblox-canjear.online malicious Sinkholed
CF Cloudflare Radar Verdict Malicious
Security threats Phishing Phishing

Forensic History & Detection Timeline

This timeline displays historical security and status checkpoints observed by the PhishDestroy automated monitoring network. It records domain lifecycle updates, scanner changes, and threat telemetry over time.
  1. Domain Status Transition Sep 13, 2026 · 00:18 UTC
    Domain state transitioned from dead to alive.
  2. Domain Status Transition Sep 11, 2026 · 00:44 UTC
    Domain state transitioned from alive to dead.
  3. VirusTotal Detections Update Jun 26, 2026 · 05:51 UTC
    VirusTotal scanner detections updated from 8 to 24. Added scanner alerts: BitDefender, Chong Lua Dao, Cluster25, Criminal IP, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, LevelBlue, Lionic, Netcraft. Resolved alerts: Webroot.

Threat Response Pipeline

Discovery
Checks
Reports
Availability
19/19
Sent Report Recorded
Stored sent-report record for registrar Dattatec Corp, hosting provider, 1 abuse contact
abuse@donweb.com
May 7, 2026

Public Blocklist Status

Evasion analysis

Cloaking & traffic-distribution check

Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.

Stored cloaking flag
Not observed
Cloaking score
0/6
Last cloaking scan

Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter

Live TDS fingerprint check
Seven Keitaro fingerprints plus a crawler-versus-browser comparison, run from the PhishDestroy scanner when this section scrolls into view.
Waiting

Stored Capture · 3 sources

Page Title
Roblox
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt · valid for 27 days

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Google Safe Browsing Flagged Social engineering checked Jun 26, 2026
Server / ASN Apache · AS27823 Dattatec.com
IP Reputation abuse score 0/100 0 reports checked Sep 13, 2026
Registrar Dattatec
IP Address 200.58.111.123 AR
GeoAR Rosario, AR
NetworkAS27823 · Dattatec.com
RegistrationCreated Aug 30, 2025
Time to First Unavailability 7 days
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, SSL SANs, timestamps
First DetectedMay 7, 2026
IoC Extractionscanned Jul 29, 20260 wallet · 0 Telegram IoCs
Submitted URLhttp://roblox-canjear.online/
Nameserversns1.donweb.comns2.donweb.comns3.hostmar.comns4.hostmar.com
MX Records0 mail.roblox-canjear.online 20 mx1.roblox-canjear.online
TLS Fingerprint
TLS Observationvalid from Apr 24, 2026scanned May 7, 2026
Favicon Hash
Case ID
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Technologies · 2 identified
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

18 / 89 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 20 detections
Criminal IP
alphaMountain.ai
BitDefender
Chong Lua Dao
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safe Browsing
Gridinsoft
Kaspersky
Lionic
Seclookup
SOCRadar
Sophos
VIPRE
Webroot

Archived Evidence

Wayback Machine Snapshot
A historical snapshot is available for evidence review
View Archive
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of roblox-canjear.online · checked Jun 26, 2026

73
Needs Work
Performance
FCP
2.61s
First Contentful Paint
LCP
5.47s
Largest Contentful Paint
CLS
0.031
Cumulative Layout Shift
TBT
34ms
Total Blocking Time
SI
4.49s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Community reports

Reported by 1 community member, first seen May 7, 2026

Stored reports
1
Unique reported URLs
1
Accepted1

Evidence & External Reports

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260507-93C135 Recipient: abuse@donweb.com
Page title stored with report: Roblox
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 13.7 KB
PDF notice generated Notice text archived (650 chars)
Abuse notice text as sent to the provider
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/roblox-canjear.online"
  title="PhishDestroy threat report for roblox-canjear.online"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>