store[.]workshopcommunitysign[.]com
“403 Forbidden”
store.workshopcommunitysign.com — Контент недоступний (HTTP 502). Уособлення бренду: Steam; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLScan malicious verdict; PhishDestroy score 100/100. Реєстратор: Global Domain Group.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies store.workshopcommunitysign.com as a recently activated domain engaged in credential harvesting operations. This domain, registered on April 28, 2026 through Global Domain Group LLC, is currently under active reconnaissance and has not yet been widely blocked by security vendors. The domain resolves to IP address 188.114.96.3 and utilizes a Let's Encrypt SSL certificate for added legitimacy during phishing operations. Despite zero detections on VirusTotal and no current entries in major threat intelligence feeds, all indicators suggest this domain is being weaponized for immediate deployment in phishing campaigns targeting unsuspecting users. Technical analysis reveals several concerning attributes about this infrastructure. The domain has zero detections across 95 VirusTotal engines and remains unlisted in all major threat intelligence platforms, despite being active for several weeks since its April registration date. The inclusion of a Let's Encrypt certificate suggests attackers are prioritizing HTTPS deployment to bypass network monitoring tools that might otherwise flag non-HTTPS domains. The registrant's use of Global Domain Group LLC, a known privacy protection registrar, further complicates attribution efforts while demonstrating deliberate operational security measures by the threat actor. Current blocklist coverage remains at zero entries, indicating this domain represents a significant blind spot in enterprise security monitoring. Users who have encountered this domain should immediately reset any credentials that may have been entered on the site. The absence of widespread blocking combined with the domain's recent activation suggests this infrastructure could escalate into more aggressive phishing campaigns targeting enterprise and consumer accounts alike. Organizations should implement immediate DNS blocking for store.workshopcommunitysign.com and 188.114.96.3 while monitoring for any suspicious login attempts from affected user populations. Given the Let's Encrypt certificate and professional appearance of the domain, users should verify any unexpected communication claiming to be from 'Workshop Community Sign' through official channels before interacting with links or entering credentials. The 5d4534 seed identifier indicates this represents a coordinated campaign that may expand to additional malicious domains sharing infrastructure patterns with this sample.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: workshopcommunitysign.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain workshopcommunitysign.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of store.workshopcommunitysign.com · checked Apr 29, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога