faceit[.]wokseason[.]com
“Steam Community”
faceit.wokseason.com — Inhalt nicht verfügbar. Markenidentität: Steam; Betrugstyp: Gaming Scam. Zusammenfassung der Beweislage: VirusTotal 14/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; PhishDestroy score 92/100. Registrar: Web Commerce Communica….
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
On July 23, 2026, investigators recorded the domain faceit.wokseason.com as an active component of a gaming‑related impersonation campaign targeting Steam. The site resolves to the IPv4 address 185.184.123.56, which is registered to AS213877 U1 DIGITAL SERVICES LTD in the Netherlands. WHOIS data show the domain was created on 11 May 2025 and is registered through Web Commerce Communications Limited. The authoritative name servers are HOLD1.LUXHOST.ORG and HOLD2.LUXHOST.ORG, both typical of bulk‑hosting services. A TLS certificate identified as “R11” was observed for the domain, indicating that HTTPS was offered at the time of capture.
The HTTP response returned a page title of “Steam Community,” matching the declared brand target of Steam and confirming the intent to masquerade as an official Steam resource. The campaign has been classified as a gaming scam, consistent with the use of the Steam brand to lure victims into credential theft or fraudulent transactions. Multi‑engine scanning on VirusTotal recorded 14 positive detections out of 93 submitted security vendors, reflecting a moderate level of consensus among scanners that the domain is malicious. The domain is listed on at least one public security blocklist and is actively blocked by the PhishDestroy mitigation service. No additional public‑reporting platforms such as Google Safe Browsing or AlienVault OTX were referenced in the available data.
As of the reporting date, the domain is marked as offline, suggesting that the operators have taken the site down or are temporarily suspending activity. However, the underlying infrastructure – the hosting provider, name server configuration, and TLS certificate – remains unchanged and could be reused for future campaigns. Defenders should continue to monitor the IP address 185.184.123.56 and the associated ASN for any resurgence, update URL filtering rules to block the fully qualified domain name, and consider adding the domain to internal blocklists.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Registration: wokseason.com
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For the registrable domain wokseason.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt