steam[.]steamproxy[.]vip
Проверка домена steam.steamproxy.vip на фишинг и безопасность
“Sign In”
steam.steamproxy.vip — Контент недоступен (HTTP 502). Олицетворение бренда: Steam; Тип мошенничества: Gaming Scam. Сводка доказательств: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
steam.steamproxy.vip is a newly registered domain (creation date February 21 2026) that mimics the Steam brand by using the page title “Sign In”. The site was hosted on IP 8.217.145.66, an address allocated to AS45102, Alibaba (US) Technology Co., Ltd., geolocated to Hong Kong. The TLS certificate presented was issued by RapidSSL TLS RSA CA G1, which does not provide any brand‑specific validation and is consistent with low‑cost certificate services often abused by malicious operators. Analysis of public threat‑intelligence feeds shows the domain appears on a single security blocklist and is listed as blocked by PhishDestroy, indicating that at least one reputable anti‑phishing service has flagged the domain as a credential‑stealing site.
VirusTotal scans reported 14 of 93 security vendors marking the domain as malicious, reinforcing the suspicion of a gaming‑related scam. The current HTTP response is offline, suggesting the operator has taken the site down, but the infrastructure—hosting provider, certificate, and domain age—remains observable. Uncertainties include the exact phishing kit or code used, the presence of any additional command‑and‑control infrastructure, and whether the domain was ever actively serving credential‑collection pages before takedown.
Defenders should add the domain and its resolving IP to blocklists, monitor for future activity from the same IP range or ASN, and enforce strict verification of Steam‑originated communications. Organizations that use Steam services should educate users to verify URLs, especially those that request sign‑in credentials, and employ multi‑factor authentication where possible. Continuous re‑evaluation of the domain’s status is recommended, as threat actors often reactivate similar infrastructure after a temporary shutdown.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание