MALICIOUS — CRITICAL
riotgames.ws: Confirmed Phishing Site
riotgames[.]
Analysis of riotgames.ws indicates an active malicious infrastructure supporting a generic phishing campaign.
- VirusTotal
- 6/91
- Blocklists
- No stored match
- Verfügbarkeit
- Nicht bestätigt
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@omegatech.sc.
The latest stored availability evidence still shows the domain reachable; 25 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
riotgames.ws — Nicht bestätigt. Zusammenfassung der Beweislage: VirusTotal 6/91 (alphaMountain.ai, Fortinet, Gridinsoft, LevelBlue, SOCRadar); URLQuery 3 alerts; Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 78/100. Registrar: Global Domain Group.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of riotgames.ws indicates an active malicious infrastructure supporting a generic phishing campaign. The domain resolves to IP 91.92.243.12 and returns HTTP 200 with the page title "Loading," suggesting a placeholder or redirect page commonly used in credential harvesting. Registration data shows the domain was created on March 12, 2026 through Global Domain Group LLC and is delegated to Cloudflare nameservers hassan.ns.cloudflare.com and tess.ns.cloudflare.com, providing anonymity and resilience. VirusTotal scans reveal that three of ninety‑five security vendors have flagged the domain, adding independent corroboration of malicious intent. While the specific payload or credential collection mechanism has not been observed, the combination of recent registration, active hosting, and multiple vendor detections constitutes strong evidence of a phishing operation. Defenders should block network resolution to 91.92.243.12, add riotgames.ws to URL filtering and domain block lists, and monitor for related traffic patterns. Incident response teams should also review logs for any attempted connections from internal hosts to this domain and advise users to avoid any unsolicited communications referencing Riot Games credentials.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | riotgames.ws |
malicious | Sinkholed |
| Cloudflare DNS | riotgames.ws |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | riotgames.ws |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
PD-20260715-46E60E Recipient: abuse@omegatech.sc Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.