login[.]workshopartistcontent[.]com
“Kirjaudu sisään”
证据摘要
PhishDestroy has identified www.login.workshopartistcontent.com as a confirmed phishing site that specifically targets users of the cs2 platform by impersonating its login page. The domain is currently offline, having been taken down after security researchers flagged its malicious activity. This brand impersonation threat is designed to steal login credentials from unsuspecting victims who believe they are accessing a legitimate cs2 service.
Technical analysis reveals that the domain was created on February 21, 2026, and resolves to the IP address 94.141.122.69. It is flagged by 13 out of 95 security vendors on VirusTotal, indicating a significant consensus among security solutions regarding its malicious nature. Additionally, the domain appears on one security blocklist, and its SSL certificate is classified as R12. The page title observed was "Kirjaudu sisään," which is Finnish for "Log in," further confirming its phishing intent. Trust scores for this domain are extremely low due to these indicators.
As the domain is now offline, the immediate risk of credential theft is mitigated, but users should remain vigilant against similar phishing attempts. PhishDestroy recommends that all users verify the authenticity of any login pages by checking the official domain of the service they intend to use. If you have already entered credentials on this site, change your passwords immediately and enable two-factor authentication on your accounts. Always double-check URLs before entering sensitive information, and report any suspicious domains to security platforms like PhishDestroy.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控