Security Scan Report: r0bl0-verify.netlify.app

Redirected to:
https://r0bl0-verify.netlify.app/
Site favicon
Submitted: Sep 17, 2026, 12:45:37 PMCompleted: Sep 17, 2026, 12:47:38 PMpubliccompleted

This website contacted 4 IPs in 2 countries across 3 domains to perform 18 HTTP transactions. The main domain is r0bl0-verify.netlify.app and was registered 13 years ago.

Submitted URL: http://r0bl0-verify.netlify.app/

Effective URL:

https://r0bl0-verify.netlify.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed Roblox phishing page on a typosquatted netlify.app subdomain: fake login form harvesting credentials to login.php, flagged by Google Safe Browsing for social engineering.

Risk Factors
Phishing kit login page mimicking Roblox on a non-official domain
Typosquatted subdomain (r0bl0) on a free hosting platform with unknown creation date
Password field harvesting credentials to a local 'login.php' action rather than the legitimate Roblox domain
Google Safe Browsing Social Engineering detection
Domain not in Cisco Umbrella top 1M while claiming to be a major brand
Domain age information unavailable

Details

Page Title

Log in to Roblox

Scan Type

public

Domain Name Analysis

Domain 'r0bl0-verify.netlify.app' uses the application-focused generic top-level domain (.app) with subdomain 'r0bl0-verify'. The second-level label 'netlify' is 7 characters long holding two vowels versus five consonants. Breaking it apart gives three words: net, li, fy. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://r0bl0-verify.netlify.app/

Page Load Overview

9.05s
Total Load Time
421 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:496 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business91% confidence
Type: webapp
Method: ml+structural

All Detected Categories

corporate business
91%
entertainment media
69%
technology software
39%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
635.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
4104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
463.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
454.192.35.109Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
184--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D2D1FD7250F450671252C0C43B66BB2E7ED3950BDA86D98072FD2BC95FC7E839D07869

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TPcTGhOlOlaeC/h3O5KkrwZN5jNzcPHHuQyaJq0haZekeM0gYrduvawyXLz4pbvT:T0TGUBZGKdcvOQyaJUtYduu2bvMEjhWs

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6211:goghXwQAYIIJmFBxsKBhgkCgDBQAIORMAcRmIBAAIgqMYgEChCAAAoBUUgL0kAQwGcjVZkgAmAYRAbIJAIAME7Ah4uFJKkSl

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:73181a3b1cfe1018
Perceptual Hash:8c8d62e2caa5f4da
Difference Hash:e77132f2b0b6e371
Wavelet Hash:f11c1e7b1cfe101c
Color Hash:#2d8659

Other Hashes

Crop Resistant:e77132f2b0b6e371

Scan History

Scan history not available

Unable to load historical scan data