Security Scan Report: cerulean-cobbler-2999e3.netlify.app

Submitted: Sep 16, 2026, 1:45:32 AMCompleted: Sep 16, 2026, 1:46:42 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Fake Roblox login on a free netlify.app subdomain that harvests username/password and 2FA codes. Not affiliated with Roblox — do not enter credentials.

Risk Factors
Roblox brand impersonation on a non-official domain (netlify.app subdomain)
Credential-harvesting login form (password field) collecting account username/email/phone
One-time code / 2FA interception flow targeting authenticator and email codes
Unranked domain presenting itself as a major brand's login page
Russian-language phishing strings ('Неверный логин или пароль', 'Введите код из приложения-аутентификатора') inconsistent with Roblox's official localization
Domain age information unavailable

Details

Page Title

Login to Roblox

Scan Type

public

Domain Name Analysis

You're looking at domain 'cerulean-cobbler-2999e3.netlify.app' on the application-focused generic top-level domain (.app) and includes subdomain 'cerulean-cobbler-2999e3'. The registrable portion 'netlify' spans 7 characters containing 2 vowels alongside 5 consonants. Breaking it apart gives 3 words: net, li, fy. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cerulean-cobbler-2999e3.netlify.app/

Page Load Overview

1.83s
Total Load Time
143 KB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:80%
Script:Cyrillic
Direction:ltr

Detection Details

HTML Lang Attribute:ru
Text Length:520 chars
Detector Agreement:100%

Website Classification

Primary Category

entertainment media93% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

entertainment media
93%
adult content
87%
technology software
62%
phishing scam
56%
gambling betting
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
43--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11032955766F304023953E4A997A7970A3195D01BE947CA543FBC1B888FCBE94ADA33CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:FrtYfWMRcy5HR2MaIyZ0RF0rmQMqOmtOuEm4uzT5HBB3f5jFpX+8OKsxOxJBuSnv:FrtToNFQZInHE5WCQsWVCWsrYHox

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11929:jAs2ACkcDiAijAQAYGJGSgSAgENAiQAgDQJqLGBNRlQUHhDHKdrAoiEyCA00QK4IpJOegMQpARA1PAADCBZgRBgJBMDMvBQI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818181800
Perceptual Hash:cccc3333338b6666
Difference Hash:103232b232323210
Wavelet Hash:dbdbdbdb18181800
Color Hash:#bf4a40

Other Hashes

Crop Resistant:103232b232323210

Scan History

Scan history not available

Unable to load historical scan data