web-roblox[.]com[.]ru
“Site Maintenance”
Résumé des preuves
This domain, web-roblox.com.ru, is a confirmed brand impersonation threat targeting Roblox users with the intent to harvest login credentials. Analysis indicates the domain was designed to mimic the official Roblox platform, likely through a cloned login portal or fraudulent account recovery page. The absence of SSL encryption (HTTPS) further suggests an attempt to intercept unencrypted credentials or session tokens, a common tactic in credential theft campaigns. The page title 'Site Maintenance' may have been used to deceive users into believing the site was temporarily unavailable, while actually concealing malicious activity or preparing for an attack. Technical evidence supports the classification of this domain as a high-confidence phishing threat. The domain was created on January 11, 1997, though this date may reflect domain tasting or registry abuse, as it predates the Roblox platform. It is flagged by 18 out of 95 security vendors on VirusTotal, indicating broad detection across multiple threat intelligence sources. The domain appears on at least one security blocklist and is currently offline, suggesting takedown action or evasion. It resolves to IP address 38.242.239.105, hosted in France under AS51167 (Contabo GmbH), a provider frequently abused for malicious infrastructure due to its permissive hosting policies and bulk IP allocations. Users who visited web-roblox.com.ru should assume their credentials or personal information may have been compromised. Immediate action is required: reset passwords for Roblox and any accounts where the same credentials were reused. Enable multi-factor authentication (MFA) on all critical accounts to mitigate unauthorized access. Monitor financial and gaming accounts for unauthorized transactions or activity. If personal or payment details were entered, consider placing a fraud alert with credit bureaus and reviewing credit reports for suspicious activity. Organizations should block the domain and IP at the network perimeter and update endpoint protection rules to prevent future access.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif