stealthcheats[.]cc
Analyse phishing et sécurité de stealthcheats.cc
“Stealth [SA:MP/CR:MP]”
stealthcheats.cc — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Discord; Type d'arnaque : Social Media Phishing. Résumé des preuves: VirusTotal 3/95 (alphaMountain.ai, Forcepoint ThreatSeeker, G-Data); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. Bureau d’enregistrement: NameCheap.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain stealthcheats.cc was registered through NameCheap, Inc. on July 05, 2025 and is currently listed as offline. DNS resolution points to IP address 198.177.120.138, which belongs to the Netherlands under ASN 22612, also owned by NameCheap, Inc. The hosting IP has been flagged by two independent blocklists, PhishDestroy and ScamSniffer, and appears on two additional security blocklists, reinforcing its malicious reputation. The site presented an SSL certificate issued by Sectigo Public Server Authentication CA DV R36, indicating that TLS was correctly configured despite the underlying fraudulent activity.
Gridinsoft assigned a trust score of 0 out of 100, reflecting a complete lack of confidence in the domain’s legitimacy. VirusTotal analysis shows that three of ninety‑five scanning engines flagged the domain, providing additional corroboration of malicious intent. The page title returned by the server is "Stealth [SA:MP/CR:MP]", which does not directly reference the targeted brand, yet intelligence categorises the infrastructure as a social‑media phishing campaign that impersonates Discord.
The exact phishing payload, credential‑capture mechanisms, and any associated command‑and‑control infrastructure remain unverified, as no further content analysis is available. Defenders should block traffic to 198.177.120.138 and add stealthcheats.cc to internal URL filtering policies. Continuous monitoring of NameCheap‑registered domains and the identified ASN is advised, as the registrar’s infrastructure is frequently leveraged for similar brand‑impersonation campaigns.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif