rbxcdn[.]vercel[.]app
“Log in to Roblox”
证据摘要
The domain rbxcdn.vercel.app is assessed at an elevated risk level for brand impersonation, specifically targeting the Roblox brand. The domain was designed to deceive users into believing they are interacting with a legitimate Roblox service, potentially leading to the theft of login credentials and other sensitive information.
Analysis indicates that the domain was registered through Vercel Inc., a popular web development platform. The domain resolves to the IP address 64.29.17.67, which is located in the United States and is associated with Amazon.com, Inc. (AS16509). The SSL certificate is issued by Google Trust Services, which could lend a false sense of security to unsuspecting users. The domain has been flagged by 18 out of 95 security vendors on VirusTotal, suggesting a moderate level of detection and recognition as a threat. Additionally, the domain appears on two security blocklists: PhishDestroy and PhishingDB. The page title 'Log in to Roblox' further reinforces the impersonation, as it closely mimics the title of a legitimate Roblox login page. The domain has been taken offline, but its prior existence and threat indicators suggest it was actively used for phishing attacks.
To mitigate the risks associated with brand impersonation, Roblox and its users should be vigilant and implement several measures. Roblox should consider adding additional security features to their domain names, such as DMARC, SPF, and DKIM records, to prevent unauthorized use of their brand. Users should be educated to verify the URL and SSL certificate of any Roblox-related page they visit, and to report any suspicious activity to Roblox's support team. Additionally, Roblox can work with domain registrars and web hosting providers to monitor and take down any domains that impersonate their brand. Security teams should also continue to monitor the domain for any signs of resurgence and ensure that it remains on relevant blocklists to protect users from potential future threats.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
技术
识别出 2 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控