cashoutrewards[.]roblox-635[.]workers[.]dev
“Suspected phishing site | Cloudflare”
cashoutrewards.roblox-635.workers.dev — Контент недоступен. Тип мошенничества: Fake Airdrop. Сводка доказательств: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, Emsisoft, Fortinet); PhishDestroy score 99/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy identifies cashoutrewards.roblox-635.workers.dev as an active crypto-drainer phishing domain designed to steal cryptocurrency from unsuspecting users by impersonating the official Roblox cashout rewards portal. The site prompts visitors to connect their crypto wallets to allegedly claim rewards, but instead siphons all assets into attacker-controlled addresses. Technical analysis reveals the domain resolves to IP 188.114.97.3, a Cloudflare Worker instance that bypasses traditional hosting scrutiny. The threat combines social engineering with on-chain theft, targeting users familiar with Roblox’s reward ecosystem and leveraging the credibility of the roblox-635.workers.dev subdomain. This domain was flagged under investigation with unique seed d4ad31 after VirusTotal scans returned 0 detections out of 95 engines as of initial analysis. The registrar is Cloudflare, Inc., and the SSL certificate is issued by Let’s Encrypt, which does not imply legitimacy. Public blocklist counts remain unverified due to the site’s recent activation, but the combination of a fresh Cloudflare Worker deployment and zero detections signals high-risk evasion tactics. The infrastructure footprint is minimal and ephemeral, typical of crypto-drainer operations, designed to disappear before security teams can respond. The domain linked to this threat was registered anonymously and is hosted within Cloudflare’s serverless environment, making takedown and traceback efforts significantly more difficult. Users who visited cashoutrewards.roblox-635.workers.dev should immediately disconnect their crypto wallets from any active sessions using the wallet’s built-in disconnect function. Revoke any token approvals granted to unknown or suspicious domains via tools like revoke.cash or Etherscan’s token approval checker. Do not attempt to reconnect or re-enter private keys or seed phrases, even if the site requests it for “verification.” Report this domain to PhishDestroy using the unique seed d4ad31 for inclusion in the global phishing blocklist. Enable hardware wallet signing for additional security and monitor all wallet transactions for unauthorized transfers. Consider using a dedicated browser profile for Web3 interactions and disable auto-connect features where possible.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of cashoutrewards.roblox-635.workers.dev · checked Apr 6, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание