s[.]teams-si[.]com
“Sign In”
Сводка доказательств
PhishDestroy has identified s.teams-si.com as a confirmed brand impersonation threat targeting Steam users. This domain was designed to mimic the official Steam login interface, tricking victims into entering their account credentials. The site's page title, 'Sign In,' directly reflects its fraudulent purpose, and no drainer kit was detected in this case.
The technical indicators for s.teams-si.com are alarming. VirusTotal reports a detection rate of 11 out of 95 security vendors, indicating widespread recognition of its malicious nature. The domain was registered on October 9, 2025, through GRANSY S.R.O D/B/A SUBREG.CZ, and resolves to IP address 188.114.97.3. It does not have an SSL certificate, which is a red flag for legitimate services. Furthermore, the domain appears on one security blocklist and is flagged by Google Safe Browsing as phishing.
As of the latest check, s.teams-si.com has been taken offline, mitigating immediate risk. However, users who may have visited the site before it was shut down should change their Steam passwords and enable two-factor authentication immediately. PhishDestroy recommends remaining vigilant against similar phishing attempts and always verifying URLs before entering credentials.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: teams-si.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain teams-si.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание