roblox[.]com[.]gy
“Roblox”
Resumen de las pruebas
The domain roblox.com.gy was observed resolving to the IP address 128.116.102.3, an address located in the United States and announced by ASN AS22697, which is registered to Roblox. This alignment of the IP with the legitimate Roblox network is atypical for a brand‑impersonating site and suggests an attempt to lend credibility to the malicious host. The domain’s authoritative nameservers are ns1.eggywall.cc and ns2.eggywall.cc, which are unrelated to Roblox’s official DNS infrastructure, indicating a distinct hosting environment. The site employed Amazon Web Services components, including Amazon S3 storage, and was delivered over HTTP/3 with HSTS enforcement, while the front‑end framework was identified as AngularJS. The TLS certificate was issued by Let’s Encrypt (E7), a free certificate authority commonly used by both benign and malicious operators.
The page title returned by the server was simply "Roblox," matching the targeted brand and reinforcing the impersonation narrative. Security telemetry shows the domain appearing on a single blocklist and being actively blocked by PhishDestroy. AlienVault OTX recorded the domain in two separate threat‑intel pulses, providing external corroboration of malicious activity. Gridinsoft assigned a trust score of 0 out of 100, reflecting a high confidence in its malicious nature. VirusTotal scans reported 15 detections out of 95 scanned vendors, confirming that multiple security products have flagged the domain as hostile.
The registrar listed for the domain is GYNIC Direct, a registrar that does not appear to be associated with Roblox’s official registration channels. The overall risk assessment was elevated, and the domain’s status is currently offline, indicating that the malicious operation has been taken down or is no longer serving content.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.