hltvv[.]com
“HLTV.org - Official Counter-Strike 2 News and Statistics - Esports Portal”
This domain, hltvv.com, is flagged as an elevated-risk phishing resource specializing in brand impersonation and fake login credential harvesting. Analysis indicates the infrastructure is designed to mimic legitimate authentication portals, tricking users into submitting sensitive account details under false pretenses. The threat type aligns with credential theft campaigns observed in recent phishing operations, where attackers replicate corporate or financial service login interfaces to capture usernames, passwords, and multi-factor authentication codes. Infrastructure analysis reveals the domain was registered on March 27, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-volume phishing registrations. It resolves to the IP address 172.67.194.72, a Cloudflare proxy endpoint commonly used to obfuscate malicious hosting origins. Detection metrics show 1 of 95 security vendors on VirusTotal flagged the domain as malicious, while AlienVault OTX records its presence in one threat intelligence pulse. The domain appears on a single security blocklist and was actively blocked by one anti-phishing system prior to being taken offline. The creation date discrepancy (2026) suggests either a typographical error in registration records or an attempt to evade temporal-based reputation filtering. To mitigate risks associated with this brand impersonation phishing campaign, organizations should implement the following controls: Immediately add hltvv.com and its resolving IP 172.67.194.72 to web proxy and DNS blocklists. Deploy email filtering rules to quarantine messages containing the domain or its subdomains, particularly those impersonating login prompts from financial institutions or enterprise services. Conduct user awareness training focusing on identifying fake authentication portals, including verification of SSL certificates, domain spelling, and URL structure. For endpoints that may have interacted with the domain, initiate credential rotation for any accounts accessed during the exposure window, prioritizing accounts with administrative or financial privileges. Network administrators should review logs for connections to 172.67.194.72 and correlate with authentication attempts to identify potential compromised accounts.
발신 보고서 기록
제출된 증거 스냅샷
- 전송됨
- 원장 기록
- 1
- 사건 ID
PD-20260327-BDBD80- 캡처된 페이지 제목
- HLTV.org - Official Counter-Strike 2 News and Statistics - Esports Portal
- PDF 자료
- PDF 증거
증거 전문
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
네트워크 보안 인텔리전스 Registrar context
위협 대응 Pipeline
차단 목록 범위
출처 10개 · 2026년 8월 9일 동기화
탐지 타임라인
저장된 관찰 결과를 시간순으로 표시합니다.
-
VirusTotal
VirusTotal: 1 → 1
-
가용성
가용성: 최초 관찰 상태 dns_inactive
f93a11f87e4d -
가용성
가용성: dns_inactive → unknown
b2864caa19de -
가용성
가용성: unknown → dns_inactive
9474cbfb38b3 -
가용성
가용성: dns_inactive → inactive
1e295f64526c -
가용성
가용성: inactive → dns_inactive
f52d526b76a1 -
가용성
가용성: dns_inactive → unknown
43d447c60fb4 -
가용성
가용성: unknown → inactive
494922461e5b -
가용성
가용성: inactive → unknown
a95f53bca36e -
가용성
가용성: unknown → dns_inactive
6dfe9145995c
모두 보기 (7)
-
가용성
가용성: dns_inactive → inactive
6145d170feed -
가용성
가용성: inactive → dns_inactive
641ed81dc4d5 -
가용성
가용성: dns_inactive → unknown
61e0a40880f0 -
가용성
가용성: unknown → inactive
aad7b3c1f4be -
가용성
가용성: inactive → unknown
1afa6d57a13c -
가용성
가용성: unknown → dns_inactive
d0b7046e8c2f -
가용성
가용성: dns_inactive → inactive
e134e0f16231
저장된 캡처
도메인 인텔리전스
기술 세부 정보DNS, TLS 이름 및 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
포렌식 인텔리전스
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of hltvv.com · checked Jun 26, 2026
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.
모든 도메인 확인
저장된 차단 목록, WHOIS, DNS 및 공개 스캔 증거를 사용한 위협 분석
지금 스캔하기피싱 신고
의심스러운 도메인을 당사의 위협 데이터베이스에 신고해 주세요 — 커뮤니티를 보호해 주세요
보고서실시간 위협 정보
최근 피싱 보고서 및 관찰된 가용성 변경 사항
모니터링