faceitt[.]verifytf2[.]com
فحص التصيد والأمان للنطاق faceitt.verifytf2.com
“GO VERIFY YOURSELF”
faceitt.verifytf2.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Steam; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 14/95 (alphaMountain.ai, Certego, CRDF, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 97/100. مسجّل النطاق: Dominet (HK).
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain faceitt.verifytf2.com indicates it was actively involved in a brand-impersonation campaign targeting Steam users. The domain was registered on October 31, 2025, through Dominet (HK) Limited and resolved to the IP address 104.21.64.95, which is associated with Cloudflare, Inc. (AS13335) in the United States. The domain utilized Cloudflare nameservers (josephine.ns.cloudflare.com and newt.ns.cloudflare.com) and lacked an SSL certificate, increasing its risk profile for credential interception. Security vendor detections on VirusTotal showed 14 out of 95 engines flagging the domain as malicious, a signal of elevated risk but not universal consensus.
Additional trust assessments reinforce this concern: Gridinsoft assigned a trust score of 0/100, Scamadviser rated it 1/100, and the domain appeared on at least one security blocklist. The page title, 'GO VERIFY YOURSELF,' suggests an attempt to prompt users into submitting credentials under false pretenses, consistent with phishing tactics targeting Steam accounts. At the time of this report (July 23, 2026), the domain has been taken offline, and no live content is accessible.
However, the infrastructure and detection history remain relevant for historical analysis and threat correlation. Defenders should treat this domain as confirmed malicious and include it in blocklists or monitoring systems to prevent potential reuse. While the exact phishing kit or payload is not specified in available data, the combination of brand impersonation, low trust scores, and vendor detections strongly supports its classification as a credential-theft operation.
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: verifytf2.com
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain verifytf2.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب