rroblox[.]co
rroblox.co — Неперевірений. Уособлення бренду: Roblox; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 12/92 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CyRadar); Google Safe Browsing flagged; PhishDestroy score 91/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, www.rroblox.co, is identified as a high-risk credential theft operation targeting users of the Roblox gaming platform. Analysis indicates the site employs brand impersonation techniques to mimic the legitimate Roblox login interface, likely harvesting usernames and passwords for subsequent unauthorized account access or resale. No evidence of cryptocurrency drainer functionality was observed, distinguishing this as a focused credential harvesting campaign rather than a broader financial fraud operation.
Technical indicators confirm the domain's malicious infrastructure. The domain was registered on May 10, 2026, through an undisclosed registrar, with an SSL certificate issued by Let's Encrypt (R13). It resolves to the IP address 62.171.141.207, hosted by a provider in Germany. Detection metrics include a VirusTotal score of 18/95 security vendors flagging the domain, while Google Safe Browsing explicitly classifies it as phishing. The domain appears on one security blocklist, and additional protective measures have been implemented by third-party threat intelligence platforms.
As of the latest assessment, www.rroblox.co has been taken offline, reducing immediate exposure risk. However, residual threats persist, including potential reuse of harvested credentials across other platforms due to common password reuse practices. Users who interacted with the domain are advised to immediately reset passwords for Roblox and any other accounts sharing the same credentials. Organizations should monitor for credential-stuffing attempts originating from this campaign and consider implementing multi-factor authentication to mitigate future risks associated with similar credential theft operations.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Технології · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога