store[.]gerald-main[.]shop
“Anmelden”
store.gerald-main.shop — Контент недоступен (HTTP 502). Олицетворение бренда: Steam; Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 16/93 (ADMINUSLabs, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of store.gerald-main.shop was performed on July 23, 2026 following its removal from active service. The domain was registered on February 21, 2026 and resolves to the IP address 104.21.55.252, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. No TLS certificate was presented during the brief connection attempt, indicating that the site operated without HTTPS protection. The only visible page element captured before takedown was the title tag "Anmelden," a German term for "login," which aligns with the reported brand impersonation of Steam.
Infrastructure signals show a Gridinsoft trust score of 0 out of 100 and the domain appears on a single external security blocklist. VirusTotal scans reported that 16 of 93 antivirus engines flagged the domain, and PhishDestroy listed the site as blocked for phishing activity. The combination of a newly created domain, low trust rating, lack of encryption, and multiple vendor detections suggests a deliberate attempt to harvest credentials by masquerading as a Steam login portal. However, because the site is currently offline, content analysis and payload inspection are not possible, leaving the exact phishing kit or credential capture method unverified.
Defenders should continue to block the domain and its associated IP address at network perimeter devices, update URL filtering and host‑based blocklists, and monitor for any re‑registration attempts or similar domains that use the same branding cues. Users should be reminded that legitimate Steam services always employ HTTPS and that unsolicited login prompts referencing "Anmelden" are likely malicious. Ongoing observation of Cloudflare‑hosted IP ranges for similar activity is recommended to detect potential re‑use of this infrastructure.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание