cashoutrewards[.]roblox-635[.]workers[.]dev
“Suspected phishing site | Cloudflare”
cashoutrewards.roblox-635.workers.dev — Conteúdo indisponível. Tipo de golpe: Fake Airdrop. Resumo das evidências: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, Emsisoft, Fortinet); PhishDestroy score 99/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies cashoutrewards.roblox-635.workers.dev as an active crypto-drainer phishing domain designed to steal cryptocurrency from unsuspecting users by impersonating the official Roblox cashout rewards portal. The site prompts visitors to connect their crypto wallets to allegedly claim rewards, but instead siphons all assets into attacker-controlled addresses. Technical analysis reveals the domain resolves to IP 188.114.97.3, a Cloudflare Worker instance that bypasses traditional hosting scrutiny. The threat combines social engineering with on-chain theft, targeting users familiar with Roblox’s reward ecosystem and leveraging the credibility of the roblox-635.workers.dev subdomain. This domain was flagged under investigation with unique seed d4ad31 after VirusTotal scans returned 0 detections out of 95 engines as of initial analysis. The registrar is Cloudflare, Inc., and the SSL certificate is issued by Let’s Encrypt, which does not imply legitimacy. Public blocklist counts remain unverified due to the site’s recent activation, but the combination of a fresh Cloudflare Worker deployment and zero detections signals high-risk evasion tactics. The infrastructure footprint is minimal and ephemeral, typical of crypto-drainer operations, designed to disappear before security teams can respond. The domain linked to this threat was registered anonymously and is hosted within Cloudflare’s serverless environment, making takedown and traceback efforts significantly more difficult. Users who visited cashoutrewards.roblox-635.workers.dev should immediately disconnect their crypto wallets from any active sessions using the wallet’s built-in disconnect function. Revoke any token approvals granted to unknown or suspicious domains via tools like revoke.cash or Etherscan’s token approval checker. Do not attempt to reconnect or re-enter private keys or seed phrases, even if the site requests it for “verification.” Report this domain to PhishDestroy using the unique seed d4ad31 for inclusion in the global phishing blocklist. Enable hardware wallet signing for additional security and monitor all wallet transactions for unauthorized transfers. Consider using a dedicated browser profile for Web3 interactions and disable auto-connect features where possible.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of cashoutrewards.roblox-635.workers.dev · checked Apr 6, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo