MALICIOUS — CRITICAL
upgrader1[.]live
Analysis of the domain upgrader1.live indicates it is an active phishing site targeting users of Counter-Strike 2 (CS2) and Counter-Strike: Global Offensive (CS:GO) skin trading services.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@identitydigital.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
upgrader1.live — Bilinen son aktif (HTTP 301). Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 88/100. Kayıt kuruluşu: NiceNIC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Analysis of the domain upgrader1.live indicates it is an active phishing site targeting users of Counter-Strike 2 (CS2) and Counter-Strike: Global Offensive (CS:GO) skin trading services. The domain was registered on June 28, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, and remains operational as of July 12, 2026. The page title, "Топ сервис Апгрейдер скинов CS2 и CS:GO | Быстрый апгрейд предметов на Upgrader 1," explicitly references CS2 and CS:GO skin upgrades, suggesting an attempt to deceive users into submitting in-game item credentials or financial details under the guise of a legitimate trading service. Infrastructure analysis reveals the domain resolves to IP address 172.67.157.63 and employs Cloudflare for hosting and security, including HTTP/3 and HSTS. The SSL certificate is issued by Google Trust Services, which does not inherently indicate malicious activity but is commonly used by threat actors to lend false legitimacy. The domain is flagged on one security blocklist and appears in four AlienVault OTX threat intelligence pulses, confirming its classification as malicious by multiple sources. VirusTotal reports five security vendors flagging the domain out of 95, further supporting its high-risk status. The domain utilizes PHP and Unpkg technologies, which are frequently exploited in phishing campaigns for dynamic content delivery and obfuscation. No specific phishing kit or brand impersonation beyond the referenced CS2/CS:GO context is confirmed at this time. Defenders should treat this domain as a confirmed phishing threat, block it at the network level, and monitor for related indicators of compromise, including the associated IP address and SSL certificate details. Given its recent registration and active status, continued monitoring for evolving tactics or additional infrastructure is recommended.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı Registrar context
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:45:18 UTC
Teknolojiler · 5 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of upgrader1.live · checked Jul 13, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260701-30BF75 Recipient: abuse@identitydigital.com Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.