stors[.]itempowered[.]pro
“Home”
Сводка доказательств
This report details the threat posed by the domain stors.itempowered.pro. The site is an impersonation scam targeting the Counter-Strike brand. Based on the page title "Home" and the identified scam type, the site was designed to deceive users into believing it was an official Counter-Strike portal, likely to harvest credentials or distribute malware. The primary threat is brand impersonation, which can lead to account compromise or financial fraud for visitors.
Technical analysis reveals significant risk indicators. The domain was created on 2026-02-21 and is registered with PDR Ltd. d/b/a PublicDomainRegistry.com. It resolves to IP address 188.114.96.3, hosted in the US by AS13335 Cloudflare, Inc., with nameservers hope.ns.cloudflare.com and trevor.ns.cloudflare.com. The site lacks SSL encryption. VirusTotal analysis shows 17 out of 95 vendors flagged the domain as malicious, including ADMINUSLabs, BitDefender, Chong Lua Dao, Cluster25, and CRDF. The domain is listed on 1 blocklist.
The current status of the domain is DOWN/OFFLINE, meaning it is no longer accessible. The GridinSoft trust score is 0 out of 100, and the DOM risk score is 10, indicating a critical risk level. Due to the low trust score, high detection rate, and offline status, this domain poses a severe threat and should be permanently blocked.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260128-A01DFA- PDF-файл
- PDF с доказательствами
Полный текст доказательств
Policy Violations: Explicit policy to immediately suspend domains used for phishing, 419 scams, identity fraud, malware distribution without prior notice
Applicable Laws: IT Act 2000 §§66C–66D (identity theft, cheating by personation), Indian Penal Code §420 / Bharatiya Nyaya Sanhita §318 (fraud)
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/63/10a/common.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | stors.itempowered.pro |
malicious | Sinkholed |
| DNS4EU | stors.itempowered.pro |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: itempowered.pro
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain itempowered.pro behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание