# proxy-de.steganos.com — SUSPICIOUS > proxy-de.steganos.com is a medium-risk phishing domain. Stay alert and block access to protect your network from potential credential theft. ## Summary PhishDestroy identifies proxy-de.steganos.com as an active phishing domain posing a medium-level threat. This domain is involved in generic phishing attacks designed to deceive users into divulging sensitive information, including login credentials and personal data. Due to the deceptive nature of its campaigns, this domain represents a substantial risk to individuals and organizations alike. The domain proxy-de.steganos.com was registered on July 1, 1998, and is maintained through InterNetX GmbH. It currently resolves to the IP address 198.18.0.69 and appears on two security blocklists, signaling its malicious activity. Despite its long-standing registration, only three out of 95 security vendors on VirusTotal have flagged it, indicating the need for vigilance as its activity may be underreported or emerging. At present, proxy-de.steganos.com remains active and continues to be a vector for phishing attempts. PhishDestroy strongly recommends organizations to monitor and block this domain proactively. Implementing domain filtering, user awareness training, and regular threat intelligence updates will help mitigate the risk posed by this ongoing phishing threat. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: Gratis Online Web Proxy ## Domain Intelligence - Registered: 1998-07-01 04:00:00 - Expires: 2026-06-30 04:00:00 - Registrar: InterNetX GmbH - Country: DE - IP: 194.147.131.26 - IP Country: DE - IP City: Berlin - IP Org: AS31276 Die Netz-Werker Systemmanagement und Datennetze AG - Nameservers: nsa2.schlundtech.de nsb2.schlundtech.de nsc2.schlundtech.de nsd2.schlundtech.de - SSL Issuer: Let's Encrypt / R12 ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["ChainPatrol", "CRDF", "Seclookup"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "Enkrypt"] ## Evidence - Screenshot: https://urlscan.io/screenshots/01995223-efb6-7450-865c-ea08ae51ad3e.png - Cloudflare Radar: https://radar.cloudflare.com/scan/02470812-cc55-48f6-8fe9-f853b67ee2f5 - Wayback Machine: https://web.archive.org/web/https://proxy-de.steganos.com - PhishDestroy: https://phishdestroy.io/domain/proxy-de.steganos.com/ - LLM endpoint: https://phishdestroy.io/domain/proxy-de.steganos.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/proxy-de.steganos.com/ Last updated: 2026-03-19