help[.]valvesecure[.]com
“Support :: kata′”
help.valvesecure.com — Contenido no disponible (HTTP 502). Suplantación de marca: Steam; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 15/94 (BitDefender, Chong Lua Dao, Cluster25, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 95/100. Registrador: Hello Internet.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, help.valvesecure.com, poses a credential phishing threat designed to deceive users into submitting login credentials through a fraudulent support portal. Attackers often use such domains to impersonate legitimate enterprise services, tricking employees or customers into entering sensitive information like usernames, passwords, or multi-factor authentication codes. The site's infrastructure and content are engineered to appear authentic, increasing the likelihood of successful compromise, particularly in corporate environments where users may expect support-related communications. Analysis indicates this domain was registered on March 27, 2026, through Hello Internet Corp, a registrar frequently associated with high-risk domains. It is flagged by 15 out of 95 security vendors on VirusTotal, with additional detections on one security blocklist. The page title, 'Support :: kata′', suggests an attempt to mimic a legitimate support interface, while the use of Cloudflare and HTTP/3 obscures its true origin. The domain resolves to the IP address 188.114.97.3, which has been linked to other malicious activities in recent threat intelligence reports. The combination of recent registration, low trust scores, and vendor detections confirms its malicious intent. If you or someone in your organization visited help.valvesecure.com and entered credentials, immediate action is required. First, reset all passwords associated with the compromised account, prioritizing email, financial, and administrative systems. Enable multi-factor authentication if not already active, and monitor the account for unauthorized access or suspicious activity. Report the incident to your organization’s security team or IT support for further investigation, including log reviews to identify potential lateral movement or data exfiltration. Additionally, consider implementing domain-based email filtering rules to block similar phishing attempts in the future.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: valvesecure.com
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain valvesecure.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 4 identified
Server-side scripting language designed for web development.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Datos y informes externos
PD-20260327-A3C694 Recipient: abuse@hello.co ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.