Phishing detection: roblox.com.ml
Roblox Screenshot
No screenshot available yet
Captured automatically on the next refresh cycle
Investigate
Domain
roblox.com.ml2 CT hosts on apex
IP
31.56.209.148
URL
https://roblox.com.ml/users/456461417375/profile
Cert
YE2
Phishunt analysis Beta
36
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +4.5 Brand in title
- +3.4 Shared IP cluster
- +3.2 Brand favicon
- +3.0 Site cluster
- +3.0 OpenPhish
- +2.3 Cert reuse
- +2.2 Country mismatch
- +1.3 Brand typo
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.9 ASN reputation
- +0.9 Young certificate
- +0.7 Brand in cert SAN
- +0.6 Brand impersonation in path
- +0.6 Registrar reputation
- +0.6 Suspicious TLD
- +0.3 Free CA
- +0.3 Long domain
- +0.2 External scripts
- +0.1 Deep subdomain
22 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Impersonates Roblox using a domain abusing the Mali country-code TLD to mimic the official domain structure. Hosted at the same Netherlands IP as other Roblox phishing domains and reusing known phishing infrastructure. Confirmed malicious by OpenPhish.
Brand impersonation in pathShared page assetsOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-18 · confidence 78%
Domain & Network
Whois
Registrar
AGETIC Registrar
Network
Country
The Netherlands
Hosting
SWISSNET LLC
ASN
AS209373
TLS Cert
YE2
External detection
OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Campaign
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise