Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 18. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

store[.]workshopcommunitysign[.]com

“403 Forbidden”

Загрозливий вердикт Критичний 100/100 оцінка доказів
Доступність Контент недоступний Вміст був недоступний під час останнього спостереження
Виявлення VirusTotal: 18/91 Уособлення бренду: Steam
29.04.2026 Steam CDN
Огляд звіту

store.workshopcommunitysign.com — Контент недоступний (HTTP 502). Уособлення бренду: Steam; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLScan malicious verdict; PhishDestroy score 100/100. Реєстратор: Global Domain Group.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Зведення доказів
КРИТИЧНИЙ
Посилання
5D453460
Оцінка
100/100

PhishDestroy identifies store.workshopcommunitysign.com as a recently activated domain engaged in credential harvesting operations. This domain, registered on April 28, 2026 through Global Domain Group LLC, is currently under active reconnaissance and has not yet been widely blocked by security vendors. The domain resolves to IP address 188.114.96.3 and utilizes a Let's Encrypt SSL certificate for added legitimacy during phishing operations. Despite zero detections on VirusTotal and no current entries in major threat intelligence feeds, all indicators suggest this domain is being weaponized for immediate deployment in phishing campaigns targeting unsuspecting users. Technical analysis reveals several concerning attributes about this infrastructure. The domain has zero detections across 95 VirusTotal engines and remains unlisted in all major threat intelligence platforms, despite being active for several weeks since its April registration date. The inclusion of a Let's Encrypt certificate suggests attackers are prioritizing HTTPS deployment to bypass network monitoring tools that might otherwise flag non-HTTPS domains. The registrant's use of Global Domain Group LLC, a known privacy protection registrar, further complicates attribution efforts while demonstrating deliberate operational security measures by the threat actor. Current blocklist coverage remains at zero entries, indicating this domain represents a significant blind spot in enterprise security monitoring. Users who have encountered this domain should immediately reset any credentials that may have been entered on the site. The absence of widespread blocking combined with the domain's recent activation suggests this infrastructure could escalate into more aggressive phishing campaigns targeting enterprise and consumer accounts alike. Organizations should implement immediate DNS blocking for store.workshopcommunitysign.com and 188.114.96.3 while monitoring for any suspicious login attempts from affected user populations. Given the Let's Encrypt certificate and professional appearance of the domain, users should verify any unexpected communication claiming to be from 'Workshop Community Sign' through official channels before interacting with links or entering credentials. The 5d4534 seed identifier indicates this represents a coordinated campaign that may expand to additional malicious domains sharing infrastructure patterns with this sample.

VirusTotal
VirusTotal
18 det.
DNS Security
1/12
URLScan
URLScan
ScamAdviser
Scamadviser
1/100
Сертифікат TLS
Let's Encrypt
Вік
3 mo
Зафіксований статус
Контент недоступний 502
PhishDestroy
DestroyList
У списку
Обсяг даних VirusTotal 18 / 91 URLQuery не перевірено PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict malicious Блокування DNS 1/12 TLS valid certificate, 89d WHOIS 3 mo old Знімок екрана 2 captures · 2 sources Ланцюжок перенаправлень не досліджено Scamadviser 1/100
Розвіддані з мережевої безпеки
DNS Provider Blocks 1 / 12
Brand Hop

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
13/14

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
403 Forbidden
Сертифікат TLS
Valid transport encryption · Виданий Let's Encrypt · valid for 89 days

Аналітика доменів

Домен
URLScan Verdict Шкідливий score 100 Phishing brand: Steam report ↗
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутація Edge-IP не пов’язана з цим доменом.
Registrar (base domain) Global Domain Group US(US)
IP-адреса 188.114.96.3 CDN
ГеолокаціяCA Toronto, CA
МережаAS13335 · CloudFlare, Inc.
Зворотний пошук IPviewdns.info → rapiddns.io →
Початкова IP-адреса прихована за проксі CDN. Результати зворотного IP для крайової адреси містять непов’язаних орендарів; для пошуку джерела потрібен пасивний DNS або дані прозорості сертифіката.
Registration (base domain)workshopcommunitysign.com · Створено 29.04.2026 (102d)
Статус HTTP502 Error
Час до першої недоступності 13 days
Що ми враховуємо Час, що минув від першого збереженого звіту про порушення до першого спостереження, що вміст був недоступний. Це не встановлює причину.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено29.04.2026
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttps://store.workshopcommunitysign.com/sharedfiles/filesdetails/storm_blade/
Сервери іменjonah.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 28.04.2026scanned 29.04.2026
TLS SAN Domainsworkshopcommunitysign.com
ICANN OVERSIGHT Registration: workshopcommunitysign.com

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain workshopcommunitysign.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Технології · 2 identified
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% впевненості
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

18 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
Cluster25
CRDF
CyRadar
ESET
Emsisoft
Fortinet
G-Data
Gridinsoft
Lionic
MalwareURL
Netcraft
Sophos
URLQuery
VIPRE
Webroot
Аналіз продуктивності сайту

Google PageSpeed Insights — mobile performance audit of store.workshopcommunitysign.com · checked Apr 29, 2026

80
Needs Work
Performance
FCP
3.36s
First Contentful Paint
LCP
3.98s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
54ms
Total Blocking Time
SI
3.85s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Докази та зовнішні звіти

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/store.workshopcommunitysign.com"
  title="PhishDestroy threat report for store.workshopcommunitysign.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.