store[.]gerald-main[.]shop
“Anmelden”
store.gerald-main.shop — 内容不可用 (HTTP 502). 品牌冒充:Steam; 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 16/93 (ADMINUSLabs, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of store.gerald-main.shop was performed on July 23, 2026 following its removal from active service. The domain was registered on February 21, 2026 and resolves to the IP address 104.21.55.252, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. No TLS certificate was presented during the brief connection attempt, indicating that the site operated without HTTPS protection. The only visible page element captured before takedown was the title tag "Anmelden," a German term for "login," which aligns with the reported brand impersonation of Steam.
Infrastructure signals show a Gridinsoft trust score of 0 out of 100 and the domain appears on a single external security blocklist. VirusTotal scans reported that 16 of 93 antivirus engines flagged the domain, and PhishDestroy listed the site as blocked for phishing activity. The combination of a newly created domain, low trust rating, lack of encryption, and multiple vendor detections suggests a deliberate attempt to harvest credentials by masquerading as a Steam login portal. However, because the site is currently offline, content analysis and payload inspection are not possible, leaving the exact phishing kit or credential capture method unverified.
Defenders should continue to block the domain and its associated IP address at network perimeter devices, update URL filtering and host‑based blocklists, and monitor for any re‑registration attempts or similar domains that use the same branding cues. Users should be reminded that legitimate Steam services always employ HTTPS and that unsolicited login prompts referencing "Anmelden" are likely malicious. Ongoing observation of Cloudflare‑hosted IP ranges for similar activity is recommended to detect potential re‑use of this infrastructure.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。