roblox[.]com[.]ht
Análisis de phishing y seguridad de roblox.com.ht
“www.roblox.com.ht”
roblox.com.ht — Contenido no disponible (HTTP 502). Suplantación de marca: Roblox; Tipo de estafa: Gaming Scam. Resumen de las pruebas: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); 1 external blocklist match (DiscordPhishing); PhishDestroy score 95/100. Registrador: Key-Systems.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain roblox.com.ht indicates a high‑confidence brand‑impersonation campaign targeting users of the Roblox gaming platform. The domain was registered on 2026-01-04 through the registrar Key-Systems GmbH and resolves to the IPv4 address 138.226.236.35, which is assigned to Neon Core Network LLC in Belize. The page title returned by the server is "www.roblox.com.ht", confirming that the site explicitly references the target brand. The infrastructure exhibits a Gridinsoft trust score of 0 / 100, and AlienVault OTX has indexed the domain in fifteen separate threat‑intel pulses, underscoring its relevance to the security community.
Both PhishDestroy and DiscordPhishing blocklists actively deny traffic to the domain, and it appears on two additional security blocklists, further reinforcing its malicious reputation. VirusTotal scans show that eighteen of ninety‑three anti‑malware engines flag the domain, indicating that a substantial portion of commercial detection products consider it unsafe. The domain is currently taken offline, but historical evidence suggests it was used for a gaming‑scam operation that likely attempted to harvest credentials or monetize fraudulent in‑game transactions. No SSL certificate details or HTTP response codes are available, and the site’s content has not been publicly captured, leaving the exact phishing mechanics unknown.
Defenders should immediately block both the domain and its hosting IP at perimeter defenses, update URL filtering policies to include the identified blocklists, and monitor for newly registered domains that mimic the " .com.ht" pattern combined with the Roblox brand. Ongoing threat‑intel feeds, especially AlienVault OTX and Gridinsoft, should be consulted for any resurgence of activity. Incident response teams should also advise end users to verify the authenticity of any Roblox‑related communications and to avoid entering credentials on untrusted URLs.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.