roblox[.]mq
“Catalog - Roblox”
Détection enregistrée
Alerte de dissimulation
- Type de dissimulation
content_divergence- Score de dissimulation
- 1/6
Résumé des preuves
The domain roblox.mq was registered on January 10, 2025 through Gohost (ASN 208191). It resolves to the IPv4 address 91.231.222.76, which is advertised by AS36680 Netiface LLC and geolocated to Slovenia. The authoritative name servers are ns1.eggywall.cc and ns2.eggywall.cc. The site presents an HTTP 301 redirect and serves a TLS certificate issued by Let’s Encrypt (certificate identifier E8). The domain is currently marked as high risk and remains active.
Infrastructure analysis reveals a web stack built on Nginx with HSTS enabled and front‑end assets powered by Bootstrap. The domain’s Gridinsoft trust score is 0 out of 100, indicating a malicious reputation. It is listed on two public phishing blocklists, PhishDestroy and PhishingDB, confirming active abuse. The site also enforces HTTP Strict Transport Security, which can aid in detecting spoofed connections.
Threat intelligence flags roblox.mq as a brand‑impersonation campaign targeting the Roblox brand. The page title observed on the site is “Catalog – Roblox”, and the scam is categorized as a gaming‑related fraud. VirusTotal scans have resulted in 21 out of 95 security vendors marking the domain as malicious. AlienVault OTX has cited the domain in 19 separate threat‑intel pulses. The presence on multiple blocklists and the volume of vendor detections underscore the likelihood of credential‑stealing or malicious redirects.
Given the high risk rating and confirmed active status, defenders should block both the domain name and its hosting IP at perimeter defenses. DNS sinkholing or NXDOMAIN responses for roblox.mq can disrupt victim access. Continuous monitoring of the associated name servers and ASN for new sub‑domains is advised, as well as updating detection rules to include the observed page title and TLS fingerprint. Security teams should also consider sharing indicators of compromise with industry sharing groups to accelerate broader mitigation.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Technologies
3 technologies identifiées avec une forte confiance
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of roblox.mq · checked Apr 23, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif