login[.]cs2-final[.]net
login.cs2-final.net 피싱 및 보안 점검
“Sign In”
login.cs2-final.net — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Steam; 사기 유형: Gaming Scam. 증거 요약: VirusTotal 16/93 (ADMINUSLabs, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 95/100. 등록기관: REGRU-RU.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain login.cs2-final.net was registered on February 21, 2026 through the REGRU-RU registrar and is currently reported as taken offline. DNS resolution points to IP address 104.21.40.47, which is allocated to the United States and owned by AS13335 Cloudflare, Inc. The authoritative nameservers are abdullah.ns.cloudflare.com and val.ns.cloudflare.com, confirming the use of Cloudflare’s infrastructure. No SSL/TLS certificate is presented for the host, meaning connections are not encrypted and the lack of a certificate is itself a security indicator. The site’s HTTP response includes a page title of "Sign In," matching the observed brand target of Steam, and the intelligence classifies the activity as a Gaming Scam that impersonates the Steam brand.
VirusTotal analysis shows that 16 of 93 scanning vendors flagged the domain, indicating a moderate to elevated detection consensus among commercial scanners. Additionally, the domain appears on a single external security blocklist and has been listed by the PhishDestroy blocklist service. The combination of a recent registration date, Cloudflare‑hosted IP, absent TLS, and multiple vendor detections suggests a purpose‑built impersonation campaign rather than an accidental misconfiguration.
However, the offline status prevents real‑time verification of payload delivery or credential harvesting mechanisms, leaving the exact malicious behavior uncertain. Defenders should add login.cs2-final.net to blocklists at the DNS, proxy, and endpoint layers, monitor traffic to its resolving IP for any anomalous requests, and consider tightening SSL inspection policies to catch unencrypted attempts. Continuous re‑evaluation is advised in case the domain is re‑activated or mirrors the observed pattern in future campaigns targeting Steam users.
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
Registration: cs2-final.net
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For the registrable domain cs2-final.net behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
증거 및 외부 보고서
PD-20260107-4CB940 Recipient: abuse@reg.ru 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.