# rustplus.showplusauth.com — SUSPICIOUS > rustplus.showplusauth.com mimics RustPlus login to steal credentials. This Let's Encrypt-certified domain, created March 28, 2026, has 0/95 VirusTotal. ## Summary PhishDestroy identifies rustplus.showplusauth.com as a live credential-phishing site masquerading as the RustPlus authentication portal. This domain is designed to trick players into entering their Steam or game credentials under the false pretense of “account recovery” or “login verification.” Once harvested, these credentials are used to hijack accounts, drain inventories, trade high-value items, or sell accounts on secondary markets. Users who enter their login details risk complete loss of their in-game progress and digital assets, with no guarantee of recovery. This domain was flagged by PhishDestroy on receipt of telemetry showing active campaign traffic. Intelligence shows it resolves to IP address 104.21.69.220, is registered through Metaregistrar BV, and holds a valid Let’s Encrypt SSL certificate. The domain was created on March 28, 2026, a recent registration intended to evade historical blocklists. As of this analysis, VirusTotal reports 0 detections out of 95 scanners, indicating the site remains under the radar and continues to operate unimpeded. If you visited rustplus.showplusauth.com and entered any credentials, immediately change your Steam password and revoke any active sessions via Steam Settings → Sessions. Use Steam’s two-factor authentication (2FA) if not already enabled. Scan your device with updated antivirus software and consider a password reset for any reused credentials across other platforms. Report the domain to your antivirus vendor and Steam support to aid in takedown efforts. Do not log in again until the site is confirmed blocked by your browser or security tool. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-28 13:40:47 - Registrar: Metaregistrar BV - IP: 104.21.69.220 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/449f51cd-9888-4501-bbb7-daf7e7dc610b - PhishDestroy: https://phishdestroy.io/domain/rustplus.showplusauth.com/ - LLM endpoint: https://phishdestroy.io/domain/rustplus.showplusauth.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/rustplus.showplusauth.com/ Last updated: 2026-03-28