Phishing detection: roblox.com.bi

Roblox
http://roblox.com.bi/users/146231873361/profile Access site
Screenshot
Screenshot of roblox.com.bi

Screenshot captured by urlscan.io on 2026-09-25T01:00 UTC: our own render of this page came back blank.

Investigate
URL http://roblox.com.bi/users/146231873361/profile
Phishunt analysis Beta
31 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +4.5 Brand in title
  • +4.1 Brand in screenshot
  • +4.1 Site cluster
  • +3.4 Shared IP cluster
  • +3.0 OpenPhish
  • +2.2 Country mismatch
  • +1.3 Brand typo
  • +0.9 Young certificate
  • +0.7 Brand in cert SAN
  • +0.6 Brand impersonation in path
  • +0.6 Suspicious TLD
  • +0.3 Free CA
  • +0.3 Long domain
  • +0.2 External scripts
  • +0.1 Deep subdomain
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site spoofs Roblox using a domain embedding the brand inside a foreign country-code TLD (.bi), presenting a fake user profile page. Hosted on Private Layer INC in Switzerland, it shares infrastructure with known Roblox phishing pages and is confirmed malicious by OpenPhish.

Brand impersonation in pathOpenPhishShared page assets
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-25 · confidence 70%
Domain & Network
Whois
Network
Country SwitzerlandSwitzerland
ASN AS51852
TLS Cert YR2
External detection OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Campaign
Report this phishing

Tracked from 2026-09-25 01:04 UTC  ·  Last refreshed 2026-10-01 15:30 UTC