csmoneys[.]com
“CS.MONEY — Official Website :: Trade CS:GO/CS2 skins for skins | MarketPlace”
This domain, csmoneys.com, poses a targeted credential theft threat against users of CS:GO and CS2 skin trading platforms. Analysis indicates the site impersonates legitimate skin marketplaces to harvest login credentials, payment details, and Steam account access tokens. The fraudulent page mimics the branding and interface of authentic trading platforms, increasing the likelihood of successful deception among users seeking to trade in-game items. Credential theft in this context can lead to unauthorized transactions, account takeovers, and financial losses through fraudulent skin transfers or purchases. Infrastructure analysis reveals multiple high-risk indicators. The domain resolves to IP address 188.114.97.3 and is flagged by 16 out of 95 security vendors on VirusTotal, including detections for phishing and fraudulent activity. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain was created on June 14, 2026—an anomalous future date suggesting possible registry tampering or misconfiguration. It appears on one security blocklist and is actively blocked by OISD. The SSL certificate is issued by Google Trust Services, providing a false sense of security while the underlying content remains malicious. Users who have visited csmoneys.com should immediately revoke any active sessions linked to gaming or payment accounts. Change passwords for Steam, associated email accounts, and any financial services connected to the platform. Enable multi-factor authentication (MFA) where available, particularly on Steam Guard or equivalent security features. Monitor account activity for unauthorized trades, logins, or transactions. If credentials were entered, assume they are compromised and avoid reusing them across other services. Clear browser cookies and cache to terminate any lingering sessions. Report the incident to the legitimate trading platform and consider filing a complaint with relevant consumer protection authorities.
网络安全情报 Registrar context
威胁响应 Pipeline
阻止列表覆盖
10 个来源 · 于 2026年8月9日 同步
已存储的结果证据
处置结果与下线归因
- 结果
live_content- 原因
content_served- 置信度
- 90%
检测时间线
按时间顺序显示已存储的观测记录。
-
VirusTotal
VirusTotal:16 → 16
-
可用性
可用性:首次观测为 unknown
993d00c35140 -
可用性
可用性:unknown → live_content
ede738649b99 -
可用性
可用性:live_content → unknown
176fe1395d1a -
可用性
可用性:unknown → live_content
ddeb7f440216 -
可用性
可用性:live_content → unknown
7cebcfd4071c -
可用性
可用性:unknown → live_content
a6a8c23a1c93 -
可用性
可用性:live_content → unknown
ca255b61650a -
可用性
可用性:unknown → live_content
94e66f4e122d -
可用性
可用性:live_content → unknown
d8f7d37d7f95
显示全部(1)
-
可用性
可用性:unknown → live_content
dcc8e6a97f32
已保存的截图
域名情报
技术详情DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
网站配置分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控