ruxbl66[.]blogspot[.]com
“Get robux”
ruxbl66.blogspot.com — Conteúdo indisponível. Representação da marca: Google. Resumo das evidências: VirusTotal 19/93 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); CF Radar malicious; PhishDestroy score 95/100. Registrador: MarkMonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, ruxbl66.blogspot.com, operates as a credential theft scam specifically targeting users of the Robux virtual currency platform. The page title, 'Get robux,' directly appeals to individuals seeking free or discounted in-game currency, a common tactic to lure victims into entering sensitive account credentials. Analysis indicates the site is designed to harvest login details, which may subsequently be used for unauthorized account access, financial theft, or further exploitation within the gaming ecosystem. The threat is particularly elevated for younger users or those unfamiliar with phishing techniques, as the domain mimics legitimate offers associated with the Robux brand. Infrastructure analysis reveals multiple technical indicators supporting the malicious classification of this domain. The domain resolves to the IP address 142.251.141.97, hosted under AS15169 (Google LLC) in the United States, and is associated with an SSL certificate issued by Google Trust Services (WE2). Despite its registration date of July 31, 2000, under the registrar MarkMonitor, Inc., the subdomain exhibits characteristics consistent with recent phishing activity. Detection metrics further substantiate the threat: 19 out of 95 security vendors on VirusTotal flag the domain as malicious, and it appears on at least one security blocklist. The combination of brand impersonation, credential harvesting intent, and low detection evasion suggests a calculated effort to exploit user trust in the Robux platform. Users who visited ruxbl66.blogspot.com should immediately take corrective action to mitigate potential risks. If any credentials were entered, the affected Robux account should be secured by changing the password and enabling multi-factor authentication. Additionally, users are advised to review their account for unauthorized transactions or activity and report any suspicious behavior to the platform’s official support channels. Given the domain’s current offline status, further interaction is unlikely; however, vigilance is recommended for similar scams leveraging the same tactics. Monitoring for unusual account activity and educating users about credential theft risks are critical steps in preventing future compromise.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 100% de confiançaJava is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 100% de confiançaOpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ruxbl66.blogspot.com · checked Mar 1, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo