Analysis of steam-community-proxy.synplay.cn indicates an active high‑risk phishing infrastructure observed as of July 29, 2026. The domain resolves to the IPv4 address 188.114.96.3 and is registered through 阿里云计算有限公司(万网). Creation of the domain is recorded on June 16, 2026, suggesting a recent deployment. DNS resolution is delegated to hans.ns.cloudflare.com and ollie.ns.cloudflare.com, confirming the use of Cloudflare’s authoritative name servers.
Google Safe Browsing has flagged the domain for social engineering, and VirusTotal reports that eight out of ninety‑one scanned security vendors label the domain as malicious, providing independent corroboration of its abusive nature. The domain is presently listed on a single security blocklist and is blocked by the PhishDestroy service, indicating that at least one anti‑phishing platform has taken mitigation action. No public evidence of SSL certificate details, HTTP response codes, or page title has been released, leaving the exact content of the hosted site unverified.
Defenders should treat the domain as hostile, enforce network‑level blocking, add the address 188.114.96.3 to host‑based deny lists, and monitor for any related indicators such as the Cloudflare nameservers hans.ns.cloudflare.com and ollie.ns.cloudflare.com. Continuous re‑scanning on VirusTotal and periodic checks against Google Safe Browsing are recommended to capture any changes in detection status. Given the recent registration date and confirmed presence on phishing‑specific blocklists, the domain should be considered a priority for remediation in email gateways, web proxies, and endpoint protection solutions.