rustoutpost[.]net
Verificação de phishing e segurança de rustoutpost.net
“RustOutpost | Community for RUST Skin Designers”
rustoutpost.net — Conteúdo indisponível (HTTP 502). Representação da marca: Steam; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 13/93 (alphaMountain.ai, BitDefender, Certego, CRDF, CyRadar); PhishDestroy score 89/100. Registrador: Web Commerce Communica….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
rustoutpost.net was registered on 10 November 2025 through Web Commerce Communications Limited and resolves to the IP address 185.178.208.158, which belongs to AS57724 DDOS‑GUARD LTD located in Russia. The domain is served by the nameservers ns1.ddos‑guard.net and ns2.ddos‑guard.net and does not present an SSL certificate, indicating that any traffic would be unencrypted. Passive monitoring shows the site is currently taken offline, and the domain appears on a single security blocklist; it is also listed as blocked by PhishDestroy. Reputation scoring from Gridinsoft assigns a trust score of 0 / 100, reflecting a lack of legitimacy.
Content analysis from the page title “RustOutpost | Community for RUST Skin Designers” suggests the site was positioned as a community hub for Rust skin designers, but the threat profile lists the campaign as a brand‑impersonation operation targeting Steam. No further page content has been captured, so the exact method of impersonation (e.g., login prompt, credential harvesting) remains unknown. VirusTotal reports that 13 of 93 scanning engines flag the domain, providing additional corroboration of malicious intent. The domain also appears in one AlienVault OTX pulse, further linking it to threat‑intel activity.
The combination of a low trust score, multiple vendor detections, association with a known blocklist, and attribution to a Steam brand‑impersonation campaign suggests a high likelihood that the infrastructure was used to harvest Steam credentials or to distribute malware masquerading as Steam‑related content. Defenders should continue to block rustoutpost.net at perimeter filters, add the associated IP address 185.178.208.158 to deny lists, and monitor for any future DNS resolution changes. Given the Russian hosting and the use of DDOS‑GUARD name servers, threat actors may shift to alternative IPs while retaining the same domain registration, so continuous DNS and passive DNS monitoring is recommended.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo