100-likes-roblox-game[.]pages[.]dev
“Get 100 Likes Roblox Game: Tips & Tricks! | 100 Likes Roblox Game”
100-likes-roblox-game.pages.dev — 未验证. 品牌冒充:Roblox; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Fortinet, Sophos); URLQuery 21 alerts; PhishDestroy score 68/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, 100-likes-roblox-game.pages.dev, is flagged as an active Roblox credential phishing site. Analysis indicates the page impersonates Roblox support or community features, specifically targeting users with promises of in-game likes or rewards in exchange for login credentials. The threat type is classified as a fake login portal, designed to harvest account credentials under false pretenses. Infrastructure analysis reveals the domain was registered on May 03, 2026, through Cloudflare, Inc., and currently resolves to the IP address 172.66.46.212, located in California. The domain has not been flagged by any of the 95 vendors on VirusTotal, though it appears on one security blocklist. The SSL certificate is issued by Google Trust Services (WE1), a common certificate authority, which does not mitigate the phishing risk. The page title, 'Get 100 Likes Roblox Game: Tips & Tricks! | 100 Likes Roblox Game,' further supports the credential harvesting motive by leveraging social engineering tactics. Current status remains active, with no takedown or mitigation observed as of this report. Organizations and users are advised to block the domain and IP address at the network level. End-users should be educated on recognizing phishing attempts, particularly those exploiting popular gaming platforms. Security teams are recommended to monitor for credential submissions to this domain and investigate any compromised accounts for unauthorized activity. Given the lack of detections on VirusTotal, proactive threat hunting using the provided indicators is strongly advised.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/0980151a/player_embed_es6_tcc.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | wayfarerorthodox.com |
malicious | Sinkholed |
| DNS4EU | wayfarerorthodox.com |
malicious | Sinkholed |
| Cloudflare DNS | kettledroopingcontinuation.com |
malicious | Sinkholed |
| DNS4EU | kettledroopingcontinuation.com |
malicious | Sinkholed |
| Hagezi Threat Feed | kettledroopingcontinuation.com |
malicious | Sinkholed |
| DNS4EU | immigrationacre.com |
malicious | Sinkholed |
| Hagezi Threat Feed | immigrationacre.com |
malicious | Sinkholed |
| Quad9 DNS | immigrationacre.com |
malicious | Sinkholed |
| Quad9 DNS | cdn.show-creative1.com |
malicious | Sinkholed |
| DNS4EU | cdn.show-creative1.com |
malicious | Sinkholed |
| DNS4EU | sourshaped.com |
malicious | Sinkholed |
| Quad9 DNS | sourshaped.com |
malicious | Sinkholed |
| Cloudflare DNS | sourshaped.com |
malicious | Sinkholed |
| Hagezi Threat Feed | preferencenail.com |
malicious | Sinkholed |
| Cloudflare DNS | preferencenail.com |
malicious | Sinkholed |
| Cloudflare DNS | flushpersist.com |
malicious | Sinkholed |
| Hagezi Threat Feed | flushpersist.com |
malicious | Sinkholed |
| DNS4EU | cdn.show-sb.com |
malicious | Sinkholed |
| Cloudflare DNS | cdn.show-sb.com |
malicious | Sinkholed |
| Quad9 DNS | cdn.show-sb.com |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。