cashoutrewards[.]roblox-635[.]workers[.]dev
“Suspected phishing site | Cloudflare”
cashoutrewards.roblox-635.workers.dev — İçerik kullanılamıyor. Dolandırıcılık türü: Fake Airdrop. Kanıt özeti: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, Emsisoft, Fortinet); PhishDestroy score 99/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies cashoutrewards.roblox-635.workers.dev as an active crypto-drainer phishing domain designed to steal cryptocurrency from unsuspecting users by impersonating the official Roblox cashout rewards portal. The site prompts visitors to connect their crypto wallets to allegedly claim rewards, but instead siphons all assets into attacker-controlled addresses. Technical analysis reveals the domain resolves to IP 188.114.97.3, a Cloudflare Worker instance that bypasses traditional hosting scrutiny. The threat combines social engineering with on-chain theft, targeting users familiar with Roblox’s reward ecosystem and leveraging the credibility of the roblox-635.workers.dev subdomain. This domain was flagged under investigation with unique seed d4ad31 after VirusTotal scans returned 0 detections out of 95 engines as of initial analysis. The registrar is Cloudflare, Inc., and the SSL certificate is issued by Let’s Encrypt, which does not imply legitimacy. Public blocklist counts remain unverified due to the site’s recent activation, but the combination of a fresh Cloudflare Worker deployment and zero detections signals high-risk evasion tactics. The infrastructure footprint is minimal and ephemeral, typical of crypto-drainer operations, designed to disappear before security teams can respond. The domain linked to this threat was registered anonymously and is hosted within Cloudflare’s serverless environment, making takedown and traceback efforts significantly more difficult. Users who visited cashoutrewards.roblox-635.workers.dev should immediately disconnect their crypto wallets from any active sessions using the wallet’s built-in disconnect function. Revoke any token approvals granted to unknown or suspicious domains via tools like revoke.cash or Etherscan’s token approval checker. Do not attempt to reconnect or re-enter private keys or seed phrases, even if the site requests it for “verification.” Report this domain to PhishDestroy using the unique seed d4ad31 for inclusion in the global phishing blocklist. Enable hardware wallet signing for additional security and monitor all wallet transactions for unauthorized transfers. Consider using a dedicated browser profile for Web3 interactions and disable auto-connect features where possible.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of cashoutrewards.roblox-635.workers.dev · checked Apr 6, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin