EduardGreat Nov 23, 2024 @ 8:49am
Alert - phishing community site by russians
Please help to block phishing domain ( steamcommunuty [dot] ru ) that is registered in russia and is extremly dangerous for users and for community. It is registered on timeweb registrar (it is bad reputation registrar at all) but you can help to down this fraud by mailing to abuse@timeweb [dot] ru
< >
Showing 1-12 of 12 comments
cSg|mc-Hotsauce Nov 23, 2024 @ 8:55am 
This is not new. It has been a thing for over a decade.

Report it to the content provider.

:nkCool:
EduardGreat Nov 23, 2024 @ 8:58am 
Abuse subject

Abuse text: Abuse Report: Phishing and Malicious Use of Domain steamcommunuty [dot] ru

Dear Timeweb Team,
I am writing to report the domain steamcommunuty [dot] ru as a phishing and malicious domain designed to impersonate the legitimate Steam Community website (steamcommunity [dot] com). The domain in question poses a significant security threat to users by deceiving them into believing it is an official Steam platform.

Abuse Description: The domain has been identified as actively hosting phishing pages that are designed to collect sensitive user credentials, such as Steam account logins, passwords, and payment details. This activity constitutes a violation of acceptable use policies and poses a severe threat to cybersecurity.

Similarity to Official Domain: The malicious domain is almost identical to the legitimate Steam Community domain (steamcommunity [dot] com), differing by only a minor spelling change ("community" vs. "communuty"), a classic example of typosquatting intended to deceive users.

Evidence:
- The domain's hosted content imitates the official Steam website in appearance, functionality, and branding without authorization.
- It has been reported as engaging in phishing attempts by several cybersecurity monitoring tools and end-users.
- The domain targets unsuspecting victims, resulting in account compromise and potential financial loss.
- The malicious domain hotlinks assets (e.g., logos, stylesheets, and scripts) directly from the legitimate steamcommunity.com website. This activity not only infringes upon intellectual property rights but also contributes to the deception by making the phishing site appear identical to the legitimate one.
Phishing Content:
- The domain mimics the official Steam interface to collect login credentials and financial data under false pretenses. Victims are led to believe they are logging into their genuine Steam accounts, leading to account takeovers and potential financial losses.

Violations:
- Phishing and Deception: Designed to steal sensitive data, including account credentials.
- Intellectual Property Infringement: Unauthorized use of Steam's branding, logos, and assets.
- Regional Targeting: Focused phishing attempts on Ukrainian users further escalate the severity.


Request for Immediate Action:
I kindly request that you take immediate action to investigate and suspend the domain steamcommunuty.ru to prevent further harm to users. Additionally, please escalate this issue to relevant authorities, such as local cybersecurity agencies, to ensure the responsible parties are held accountable.
EduardGreat Nov 23, 2024 @ 8:59am 
Originally posted by cSg|mc-Hotsauce:
This is not new. It has been a thing for over a decade.

Report it to the content provider.

:nkCool:
I already report it to registrar and to steam support - but more mails more actions. We are a drop in the ocean, and when we connect - we are that ocean!
Last edited by EduardGreat; Nov 23, 2024 @ 9:00am
EduardGreat Nov 23, 2024 @ 9:01am 
Another good text for abuse (please format yourself in mail agent when you send it):

The domain steamcommunuty [dot] ru is being used for phishing and malicious activities, specifically targeting users by impersonating the legitimate Steam Community website (steamcommunity [dot] com).

Details of Abuse:
- Phishing Pages: The domain hosts fraudulent content designed to collect sensitive user data, including login credentials and payment information, under false pretenses.
- Typosquatting: The domain name is intentionally misspelled to mislead users into believing they are accessing the legitimate Steam platform.
- Hotlinking Assets: The site illegally hotlinks logos, stylesheets, and other assets from steamcommunity [dot] com, infringing on intellectual property rights and reinforcing the deception.
- Referrer Exploitation: Users are redirected to this domain via deceptive links embedded in official-looking resources, further misleading them.
- Regional Targeting: The site primarily targets Ukrainian IP addresses, which suggests deliberate exploitation of regional trust factors.

Violations:
- Unauthorized use of branding and intellectual property belonging to steamcommunity [dot] com.
- Active phishing designed to defraud users and compromise their accounts.
- Abuse of redirection mechanisms to appear associated with the legitimate platform.

This domain is being used exclusively for illegal purposes and poses a serious threat to user security. Immediate suspension of steamcommunuty [dot] ru and associated services is required to mitigate ongoing harm.
cSg|mc-Hotsauce Nov 23, 2024 @ 9:04am 
Originally posted by EduardGreat:
Originally posted by cSg|mc-Hotsauce:
This is not new. It has been a thing for over a decade.

Report it to the content provider.

:nkCool:
I already report it to registrar and to steam support - but more mails more actions. We are a drop in the ocean, and when we connect - we are that ocean!

Back when Valve had Global volunteer mods, we submitted thousands of these fake Steam links to get blacklisted.

:nkCool:
13119205187923161 Nov 23, 2024 @ 9:04am 
i mean, it is admirable that you want to warn people

but these are steam user forums

the people that you would report this to are not going to be here
EduardGreat Nov 23, 2024 @ 9:25am 
Originally posted by KalCuey:
i mean, it is admirable that you want to warn people

but these are steam user forums

the people that you would report this to are not going to be here
Okay, got your point and thanks for write this.

Although support still don't react, one hour already went from my ticket send, it is a bit disappointed that users are worried about security more than the billion sized Valve corporation.
EduardGreat Nov 23, 2024 @ 9:26am 
Indifference is the worst scourge of today
13119205187923161 Nov 23, 2024 @ 9:34am 
Originally posted by EduardGreat:
Originally posted by KalCuey:
i mean, it is admirable that you want to warn people

but these are steam user forums

the people that you would report this to are not going to be here
Okay, got your point and thanks for write this.

Although support still don't react, one hour already went from my ticket send, it is a bit disappointed that users are worried about security more than the billion sized Valve corporation.

there is just so much that they can do

we are given the tools to keep us safe

as long as we practice the basics of internet safety, we are good

unfortunately, some don't

either because of fear at the moment, thinking they are getting banned

or they got greedy

or because they did not pay attention

when it comes to other sites

again, only so much they can do

as far as we know, they have reported all the sites they know about

where they are located is a big deal
EduardGreat Nov 23, 2024 @ 10:12am 
Originally posted by KalCuey:
Originally posted by EduardGreat:
Okay, got your point and thanks for write this.

Although support still don't react, one hour already went from my ticket send, it is a bit disappointed that users are worried about security more than the billion sized Valve corporation.

there is just so much that they can do

we are given the tools to keep us safe

as long as we practice the basics of internet safety, we are good

unfortunately, some don't

either because of fear at the moment, thinking they are getting banned

or they got greedy

or because they did not pay attention

when it comes to other sites

again, only so much they can do

as far as we know, they have reported all the sites they know about

where they are located is a big deal

For sure. I think you are right in your thoughts.

Nevertheless i will take actions myself to take down that phishing. And this is proof that even one can do something.

And also I still waiting response from support.

Already 2 hours and they not react, but still - they must and they will
76561199229817353 Nov 29, 2024 @ 12:16am 
Hi I don't remember my steam account password. and steam states I made too many attempts..and I should try again. However it has been 2 days ..I can't afford to loose my account again.please help
Originally posted by BIgMac:
Hi I don't remember my steam account password. and steam states I made too many attempts..and I should try again. However it has been 2 days ..I can't afford to loose my account again.please help
Dont guess the password. If you dont know it choose forgot password.
< >
Showing 1-12 of 12 comments
Per page: 1530 50

Date Posted: Nov 23, 2024 @ 8:49am
Posts: 12