rblox[.]me
“Kyxn Dev — Developer Platforms”
rblox.me — Conteúdo indisponível (HTTP 502). Representação da marca: Roblox; Tipo de golpe: Fake Airdrop. Resumo das evidências: VirusTotal 20/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender); URLQuery 15 alerts; URLScan malicious verdict; PhishDestroy score 100/100. Registrador: Namecheap.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain is flagged for elevated-risk generic phishing activity targeting software developers and platform users. Analysis indicates the site rblox.me impersonates legitimate developer services under the false pretense of a "Developer Platforms" offering, as evidenced by its page title "Kyxn Dev — Developer Platforms." The infrastructure presents multiple high-risk indicators that warrant immediate caution. Infrastructure analysis reveals the domain was registered through NAMECHEAP INC on March 29, 2026, with an anomalous future creation date suggesting potential domain spoofing techniques. It currently resolves to IP address 23.111.14.131 and employs a technology stack including Plesk, Node.js, Phusion Passenger, Nginx, and Express. Security vendor assessments show 20 out of 95 detection engines flagged the domain on VirusTotal, while it appears on one security blocklist and has been taken offline following detection. Trust scoring systems assign it a Gridinsoft score of 0/100 and Scamadviser rating of 1/100, both indicating maximum risk levels. Organizations should implement immediate mitigation measures including blocking the domain rblox.me and its associated IP 23.111.14.131 at firewall and DNS levels. Security teams should conduct credential reset procedures for any accounts that may have interacted with the domain, particularly developer credentials that could grant access to sensitive repositories or deployment systems. Additional monitoring should be implemented for the technology stack components (Node.js, Express, Nginx) which may be targeted in similar phishing campaigns. The anomalous creation date of March 2026 should be used as an additional filter criterion for detecting related malicious domains in threat intelligence feeds.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | app.injuries.lu |
malicious | Sinkholed |
| Hagezi Threat Feed | app.injuries.lu |
malicious | Sinkholed |
| Cloudflare DNS | www.robiox.com.py |
malicious | Sinkholed |
| DNS4EU | www.robiox.com.py |
malicious | Sinkholed |
| OpenDNS | www.robiox.com.py |
phishing | Phishing Block |
| DigiCert UltraDNS | www.robiox.com.py |
malicious | Sinkholed |
| Hagezi Threat Feed | www.robiox.com.py |
malicious | Sinkholed |
| Quad9 DNS | www.robiox.com.py |
malicious | Sinkholed |
| DigiCert UltraDNS | api.injuries.lu |
malicious | Sinkholed |
| Hagezi Threat Feed | api.injuries.lu |
malicious | Sinkholed |
| Cloudflare DNS | metrics.robiox.com.py |
malicious | Sinkholed |
| OpenDNS | metrics.robiox.com.py |
phishing | Phishing Block |
| DNS4EU | metrics.robiox.com.py |
malicious | Sinkholed |
| DigiCert UltraDNS | metrics.robiox.com.py |
malicious | Sinkholed |
| Hagezi Threat Feed | metrics.robiox.com.py |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of rblox.me · checked Jun 26, 2026
Evidências e relatórios externos
PD-20260329-5BE62C Recipient: abuse@sg.leaseweb.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo