tmail.shopcloneroblox.com - malicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned tmail.shopcloneroblox.com and returned a malicious verdict (score 91), categorised as phishing, credential-harvest, impersonating roblox. The page resolved to 103.129.127.238 on THIEN TUAN SOLUTION AND TECHNOLOGY COMPANY LIMITED in VN. The domain was registered 784 days ago through HOSTINGER operations, UAB. 4 domains and 4 IPs were contacted, over 10 HTTP requests. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 91) · Confidence 100%
- Scanned URL:
https://tmail.shopcloneroblox.com/ - Domain: tmail.shopcloneroblox.com · IP: 103.129.127.238 · AS135918 · VN
- Server: LiteSpeed
- Page title: TMail
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: HOSTINGER operations, UAB · domain age 784 days · created 2024-06-28
- TLS issuer: C=AT, O=ZeroSSL, CN=ZeroSSL RSA Domain Secure Site CA · valid to May 27 23: · subject CN=tmail.shopcloneroblox.com
- HTTP requests captured: 10 · cookies set: 2
- Scan tier: standard · observed 2026-08-21 14:10:09 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
Categories
- phishing
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Domain impersonates roblox (combosquat)
- Credential-harvesting form
- Untrusted certificate (CERT_HAS_EXPIRED)
Detected technologies
- LiteSpeed
Contacted infrastructure
- 103.129.127.238 - AS135918 THIEN TUAN SOLUTION AND TECHNOLOGY COMPANY LIMITED (Viet Nam)
- 104.17.25.14 - AS13335 Cloudflare, Inc. (United States)
- 142.250.195.163 - AS15169 Google LLC (India)
Observed indicators
- tmail.shopcloneroblox.com
- cdnjs.cloudflare.com
- fonts.googleapis.com
- fonts.gstatic.com
- 103.129.127.238
- 104.17.25.14
- 142.250.195.170
- 142.250.195.163
- https://tmail.shopcloneroblox.com/
- https://tmail.shopcloneroblox.com/images/icon.png
- https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.1/css/all.min.css
- https://tmail.shopcloneroblox.com/build/assets/app-BSyY0X6t.css
- https://tmail.shopcloneroblox.com/build/assets/common-CM5FHs_M.css
- https://tmail.shopcloneroblox.com/build/assets/app-DWAYDVsb.js
- https://fonts.googleapis.com/
- https://fonts.gstatic.com/
- https://fonts.googleapis.com/css2?family=Kadwa:wght@400;600;700&display=swap
- https://fonts.googleapis.com/css2?family=Poppins:wght@400;600&display=swap
- https://tmail.shopcloneroblox.com/images/logo.png
- https://tmail.shopcloneroblox.com/unlock
Questions about tmail.shopcloneroblox.com
- Is tmail.shopcloneroblox.com safe?
- No. MalwareAnalyzer scanned tmail.shopcloneroblox.com on 21 Aug 2026 and returned a malicious verdict with a score of 91 out of 100, categorised as phishing and credential-harvest. Treat it as hostile until it is re-checked.
- Does tmail.shopcloneroblox.com belong to roblox?
- No. This page claims the identity of roblox but nothing establishes that roblox operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
- How was tmail.shopcloneroblox.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of tmail.shopcloneroblox.com · Other roblox phishing domains
Scanned on MalwareAnalyzer by Cyble · Open interactive scan