1703351226[.]dojiner[.]at
“Sign In”
1703351226.dojiner.at — Контент недоступний. Уособлення бренду: Steam; Тип шахрайства: Gaming Scam. Зведення доказів: VirusTotal 23/93 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; Google Safe Browsing flagged; Spamhaus DBL_BOTNET; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: As214351.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of 1703351226.dojiner.at, created on February 21, 2026, shows that the domain is currently offline but was previously associated with a high‑risk gaming scam targeting Steam users. The site presented a page titled "Sign In," a common indicator of credential‑harvesting attempts. The domain resolves to IP address 62.60.226.105, located in Germany and registered to AS214351 FEMO IT SOLUTIONS LIMITED. Hosting is behind Cloudflare, as indicated by the authoritative nameservers arely.ns.cloudflare.com and lou.ns.cloudflare.com.
The TLS certificate is issued by Let’s Encrypt (R12), providing HTTPS with HSTS, but the certificate alone does not mitigate the malicious intent. Detection signals are strong: the domain appears on one security blocklist, is blocked by PhishDestroy, and Google Safe Browsing flags it for social engineering. VirusTotal recorded 23 detections out of 93 scanned security vendors, reinforcing the malicious classification. Additionally, Gridinsoft assigned a trust score of 0 out of 100, indicating a lack of credibility.
The web stack identified Nginx, OpenResty, and HSTS, which are consistent with many phishing infrastructures but do not provide further attribution. While the site is offline, defenders should continue to block the domain and its associated IP address at perimeter and proxy layers, monitor for any re‑registration attempts, and update phishing detection rules to include the observed page title and SSL fingerprint. Ongoing threat‑intel feeds should be queried for any resurgence of the infrastructure, and security teams should educate users about unsolicited Steam login prompts to reduce the success rate of similar impersonation campaigns.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of 1703351226.dojiner.at · checked Mar 1, 2026
Докази та зовнішні звіти
PD-20260219-232637 Recipient: abuse@as214351.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога