getrewards[.]roblox-635[.]workers[.]dev
“Suspected phishing site | Cloudflare”
getrewards.roblox-635.workers.dev — Conteúdo indisponível. Tipo de golpe: Fake Airdrop. Resumo das evidências: VirusTotal 19/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, CyRadar, ESET); PhishDestroy score 100/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain getrewards.roblox-635.workers.dev was identified as a credential theft operation specifically targeting Roblox users. Analysis indicates the site was designed to harvest login credentials by impersonating legitimate reward or account verification prompts associated with the Roblox platform. As of the latest verification, the domain has been taken offline, though it remains a documented case of brand impersonation and fraudulent credential collection. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on April 07, 2026, and resolved to the IP address 188.114.96.3, located in Canada. Security vendors flagged the domain in 20 of 95 VirusTotal scans, and it appeared on one security blocklist. The SSL certificate was issued by Let's Encrypt (serial number E7), a common choice for both legitimate and malicious sites due to its accessibility. The page title, 'Suspected phishing site | Cloudflare,' suggests automated detection by the hosting provider, which may have contributed to its eventual takedown. While the domain is currently offline, the infrastructure and tactics observed align with broader trends in credential theft targeting gaming platforms. Organizations and users are advised to monitor for similar domains leveraging Cloudflare Workers subdomains, particularly those mimicking Roblox or other high-value brands. Network-level blocking of the resolved IP (188.114.96.3) and domains with the 'roblox-###.workers.dev' pattern is recommended as a proactive measure. Users should verify the legitimacy of reward or account-related prompts by accessing official platforms directly and avoid entering credentials on untrusted sites, even if they appear visually similar to legitimate services.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of getrewards.roblox-635.workers.dev · checked Apr 7, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo