web-roblox[.]com[.]ru
“Site Maintenance”
Зведення доказів
This domain, web-roblox.com.ru, is a confirmed brand impersonation threat targeting Roblox users with the intent to harvest login credentials. Analysis indicates the domain was designed to mimic the official Roblox platform, likely through a cloned login portal or fraudulent account recovery page. The absence of SSL encryption (HTTPS) further suggests an attempt to intercept unencrypted credentials or session tokens, a common tactic in credential theft campaigns. The page title 'Site Maintenance' may have been used to deceive users into believing the site was temporarily unavailable, while actually concealing malicious activity or preparing for an attack. Technical evidence supports the classification of this domain as a high-confidence phishing threat. The domain was created on January 11, 1997, though this date may reflect domain tasting or registry abuse, as it predates the Roblox platform. It is flagged by 18 out of 95 security vendors on VirusTotal, indicating broad detection across multiple threat intelligence sources. The domain appears on at least one security blocklist and is currently offline, suggesting takedown action or evasion. It resolves to IP address 38.242.239.105, hosted in France under AS51167 (Contabo GmbH), a provider frequently abused for malicious infrastructure due to its permissive hosting policies and bulk IP allocations. Users who visited web-roblox.com.ru should assume their credentials or personal information may have been compromised. Immediate action is required: reset passwords for Roblox and any accounts where the same credentials were reused. Enable multi-factor authentication (MFA) on all critical accounts to mitigate unauthorized access. Monitor financial and gaming accounts for unauthorized transactions or activity. If personal or payment details were entered, consider placing a fraud alert with credit bureaus and reviewing credit reports for suspicious activity. Organizations should block the domain and IP at the network perimeter and update endpoint protection rules to prevent future access.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога