store[.]communityonlinestyle[.]co
“Steam Workshop::AK-47 | Eternal Decay”
store.communityonlinestyle.co — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Steam. Kanıt özeti: VirusTotal 15/94 (alphaMountain.ai, CRDF, CyRadar, ESET, Fortinet); URLQuery 3 alerts; URLScan malicious verdict; PhishDestroy score 95/100. Kayıt kuruluşu: PDR.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, store.communityonlinestyle.co, is flagged for hosting a fake login portal, a phishing technique designed to harvest user credentials. The threat type is classified as credential theft via fraudulent authentication interfaces, with an elevated risk level due to its active distribution and lack of encryption. Analysis indicates the domain was likely deployed to mimic legitimate login pages, tricking users into submitting sensitive information such as usernames, passwords, or multi-factor authentication codes. Infrastructure analysis reveals the domain was registered on March 27, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with malicious registrations. It resolves to the IP address 138.226.236.62, located in Belize under Neon Core Network LLC, a hosting provider with a history of abuse reports. VirusTotal reports 15 out of 95 security vendors detecting the domain as malicious, while it appears on one security blocklist. The domain lacks an SSL certificate, further increasing its risk profile, and is currently offline. No historical DNS records indicate prior legitimate use, suggesting the domain was created specifically for malicious purposes. Mitigation steps for this threat type include immediate blocking of the domain and its resolving IP address (138.226.236.62) at the network perimeter. Organizations should deploy email and web filtering rules to prevent user access to store.communityonlinestyle.co and monitor for credential reuse attempts from harvested data. Endpoint detection systems should be configured to flag any process attempting to connect to the domain or its IP. Security teams are advised to conduct a retrospective analysis of logs for prior connections to this infrastructure and reset credentials for any users who may have interacted with the fake login portal. User awareness training should emphasize the risks of entering credentials on unencrypted or unfamiliar login pages.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260327-34E4E5 Recipient: abuse@publicdomainregistry.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin