# lis-skinos.com — MALICIOUS > lis-skinos.com was identified in a phishing campaign targeting gamers. Avoid interacting with it and ensure your credentials remain secure. ## Summary PhishDestroy has identified the domain lis-skinos.com as involved in a generic phishing campaign targeting users interested in CS2 and DotA2 skins. The site posed as an official platform for selling game skins, potentially misleading victims into disclosing sensitive information or credentials. This represents a medium risk to users familiar with online game trading. Technical analysis reveals that lis-skinos.com was registered recently on February 7, 2025, through NiceNIC International Group Co., Limited. The domain resolved to the IP address 58.64.137.69 and was found listed on one security blocklist. VirusTotal scans flagged it by 5 out of 95 security vendors. Its page title was "LIS-SKINS — Продать Скины CS2 и DotA2 | Официальный Сайт," indicating Russian-language targeting. As of now, lis-skinos.com has been taken offline, reducing immediate threat potential. Users are advised to avoid visiting or interacting with this domain. Additionally, any credentials or personal information submitted during its active period should be considered compromised and changed promptly. Continuous monitoring for related phishing activity is recommended. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 0) - Page title: LIS-SKINS — Продать Скины CS2 и DotA2 | Официальный Сайт ## Domain Intelligence - Registered: 2025-02-07 11:38:18 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 58.64.137.69 - IP Country: HK - IP City: Tung Chung - IP Org: AS17444 HKBN Enterprise Solutions Limited - Nameservers: celeste.ns.cloudflare.com expired-ns1.niceisp.com expired-ns2.niceisp.com leonidas.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 5 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "Forcepoint ThreatSeeker", "Fortinet", "PREBYTES"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/3a5b1719-eff0-42b0-9221-84192b1ba61a.png - Cloudflare Radar: https://radar.cloudflare.com/scan/d23f8e93-6027-4ee8-a2a7-5f78ceac6699 - PhishDestroy: https://phishdestroy.io/domain/lis-skinos.com/ - LLM endpoint: https://phishdestroy.io/domain/lis-skinos.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/lis-skinos.com/ Last updated: 2026-03-19