steam[.]steamproxy[.]vip
“Sign In”
साक्ष्य सारांश
steam.steamproxy.vip is a newly registered domain (creation date February 21 2026) that mimics the Steam brand by using the page title “Sign In”. The site was hosted on IP 8.217.145.66, an address allocated to AS45102, Alibaba (US) Technology Co., Ltd., geolocated to Hong Kong. The TLS certificate presented was issued by RapidSSL TLS RSA CA G1, which does not provide any brand‑specific validation and is consistent with low‑cost certificate services often abused by malicious operators. Analysis of public threat‑intelligence feeds shows the domain appears on a single security blocklist and is listed as blocked by PhishDestroy, indicating that at least one reputable anti‑phishing service has flagged the domain as a credential‑stealing site.
VirusTotal scans reported 14 of 93 security vendors marking the domain as malicious, reinforcing the suspicion of a gaming‑related scam. The current HTTP response is offline, suggesting the operator has taken the site down, but the infrastructure—hosting provider, certificate, and domain age—remains observable. Uncertainties include the exact phishing kit or code used, the presence of any additional command‑and‑control infrastructure, and whether the domain was ever actively serving credential‑collection pages before takedown.
Defenders should add the domain and its resolving IP to blocklists, monitor for future activity from the same IP range or ASN, and enforce strict verification of Steam‑originated communications. Organizations that use Steam services should educate users to verify URLs, especially those that request sign‑in credentials, and employ multi‑factor authentication where possible. Continuous re‑evaluation of the domain’s status is recommended, as threat actors often reactivate similar infrastructure after a temporary shutdown.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।