csmoney[.]at
“CS.MONEY – Instant & Secure CS:GO/CS2 Skin Marketplace”
csmoney.at — Non vérifié. Usurpation de l'identité de la marque : Chainlink; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 97/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain csmoney.at has been identified as a brand impersonation threat targeting Chainlink, a well-known blockchain platform. This domain currently operates under the guise of a CS:GO and CS2 skin marketplace, presenting itself as "CS.MONEY – Instant & Secure CS:GO/CS2 Skin Marketplace" to deceive users into engaging with fraudulent transactions or credential harvesting schemes. Analysis indicates this domain is specifically designed to exploit trust in both the gaming and cryptocurrency communities by mimicking legitimate services. Infrastructure analysis reveals that csmoney.at is flagged by 12 of 95 security vendors on VirusTotal, indicating a consensus among multiple detection engines regarding its malicious nature. The domain resolves to the IP address 178.16.54.12 and appears on at least one security blocklist, further corroborating its association with phishing or fraudulent activity. The SSL certificate is issued by Let's Encrypt (R13), a common practice among threat actors to lend a false sense of legitimacy to malicious sites. No registrar or creation date data is available in the current intelligence, but the domain's operational pattern aligns with known phishing infrastructure. As of the latest assessment, csmoney.at has been taken offline, reducing immediate exposure to potential victims. However, the domain's prior activity and infrastructure warrant continued monitoring. Organizations and individuals are advised to block traffic to and from the IP address 178.16.54.12, update security filters to include this domain in deny lists, and educate users about the risks of brand impersonation in gaming and cryptocurrency contexts. If the domain resurfaces, further investigation into its hosting provider and associated infrastructure is recommended to mitigate broader threats.
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Server-side scripting language designed for web development.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of csmoney.at · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif