roboiltxprt[.]lol
“BLUYS Script Execution - Advanced Roblox Script Executor”
roboiltxprt.lol — Контент недоступний (HTTP 502). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 3/94 (alphaMountain.ai, Gridinsoft, SOCRadar); URLQuery 1 alert; PhishDestroy score 65/100. Реєстратор: PDR.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, roboiltxprt.lol, is flagged as a phishing site specifically designed to impersonate a legitimate Roblox script executor under the name 'BLUYS Script Execution - Advanced Roblox Script Executor.' The site targets users seeking unauthorized game modifications, tricking them into downloading malicious payloads or entering credentials. The primary threat involves credential harvesting, malware distribution, or remote code execution under the guise of providing game-enhancement tools. Analysis indicates this domain is part of a broader campaign exploiting the popularity of gaming-related utilities to compromise user systems and accounts. Infrastructure analysis reveals the domain was registered on March 29, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with abusive domains. It resolves to the IP address 188.114.96.3 and employs Cloudflare with HTTP/3, likely to obfuscate its origin and evade detection. The domain is currently offline but was flagged by 3 out of 95 security vendors on VirusTotal, including at least one major blocklist. Additionally, it holds a trust score of 0/100, further confirming its malicious nature. The use of Cloudflare and the domain's recent creation align with tactics commonly observed in phishing and malware distribution operations. Users who visited roboiltxprt.lol should assume potential compromise and take immediate action. First, terminate any active downloads or installations from the site and disconnect the affected device from the network. Run a full system scan using updated security tools to detect and remove any malicious artifacts. If credentials were entered, reset passwords for all associated accounts, particularly Roblox and any linked email or payment services, using a separate, trusted device. Monitor accounts for unauthorized activity and enable multi-factor authentication where available. Given the elevated risk level, consider reformatting the device if malware is confirmed or if the system exhibits unusual behavior.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/8e54e4ea/player_embed_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of roboiltxprt.lol · checked Jun 26, 2026
Докази та зовнішні звіти
PD-20260329-C3107E Recipient: abuse@publicdomainregistry.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога