rbxloit[.]live
“Roblox Executor - Unlock Your Potential”
Сохранённое обнаружение
Обнаружена маскировка
- Тип маскировки
content_divergence- Оценка маскировки
- 1/6
Сводка доказательств
The domain rbxloit.live poses a brand impersonation threat specifically targeting the Roblox community. It presents itself as a tool called "Roblox Executor" with the tagline "Unlock Your Potential," which is a common lure used by scammers to trick users into downloading malicious software or sharing login credentials. This type of threat is particularly dangerous because it exploits the trust that players have in the Roblox ecosystem, often leading to account theft or device compromise. The site is currently offline, but its mere existence indicates a coordinated effort to defraud users.
PhishDestroy's investigation uncovered several red flags. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, a registrar often associated with questionable domains. It resolves to the IP address 172.67.214.85, which is linked to Cloudflare, a service commonly used by scammers to mask their true hosting location. Security scans on VirusTotal show that 3 out of 95 security vendors flag this domain as malicious, and it also appears on one security blocklist. The SSL certificate is issued by Google Trust Services, which is legitimate, but that does not guarantee the site's safety—many phishing sites use valid certificates.
If you have visited rbxloit.live or entered any personal information, take immediate action. Change your Roblox password and enable two-factor authentication if you haven't already. Run a full antivirus scan on your device to check for malware. Monitor your accounts for any suspicious activity, and consider reporting the incident to Roblox support. PhishDestroy advises users to always verify the authenticity of Roblox-related tools through official channels and to avoid downloading executables from unverified sources. Staying vigilant is key to avoiding these impersonation scams.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 4 технологии с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание