store[.]workshopartistcontent[.]com
“Steam Workshop::Glock-18 | Carved arabesque”
store.workshopartistcontent.com — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Counter-strike; 사기 유형: Crypto Scam. 증거 요약: VirusTotal 12/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CyRadar); URLScan malicious verdict; PhishDestroy score 86/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain www.store.workshopartistcontent.com was registered on February 21, 2026 and is presently taken offline, but historical evidence shows it was used for a crypto‑draining operation that impersonated the Counter‑Strike brand. The site resolved to the IPv4 address 94.141.122.69, which is allocated to AS205775 (NEON CORE NETWORK LLC) in Finland. An SSL certificate identified as R12 was presented, indicating a low‑trust certificate that is typical of malicious infrastructure. The page title returned by the server, "Steam Workshop::Glock-18 | Carved arabesque," directly references a Steam Workshop item, confirming the intent to mimic official Valve content and lure users familiar with the Counter‑Strike ecosystem.
Threat intelligence feeds have recorded the domain on a single security blocklist and it has been actively blocked by the PhishDestroy service. Reputation scoring from Gridinsoft rates the domain at 0 / 100, reflecting an absence of trust. VirusTotal analysis shows that 12 of 93 scanning engines flagged the domain, reinforcing the suspicion of malicious activity.
The elevated risk rating aligns with the observed crypto‑scam behavior and brand impersonation. While the site is no longer reachable, defenders should continue to monitor the associated IP range for re‑use, enforce DNS‑level blocks for the domain and any sub‑domains, and update endpoint and web‑filter policies to reject traffic to the identified IP. Additional surveillance of newly registered domains that reference Steam Workshop terminology or Counter‑Strike assets is advised, as the pattern suggests a broader campaign that may resurface under new domains.
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.