geronimomensteambinder.online - malicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned geronimomensteambinder.online and returned a malicious verdict (score 73), categorised as phishing. The page resolved to 185.158.133.1 on Internet Utilities Europe and Asia Limited in PL. The domain was registered 0 days ago through Name.com, Inc.. 1 domain and 1 IP were contacted, over 19 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 73) · Confidence 85%
- Scanned URL:
https://geronimomensteambinder.online/binder - Domain: geronimomensteambinder.online · IP: 185.158.133.1 · AS13335 · PL
- Server: cloudflare
- Page title: The Binder — Ethos
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: Name.com, Inc. · domain age 0 days · created 2026-08-19
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 17 22: · subject CN=geronimomensteambinder.online
- HTTP requests captured: 19 · cookies set: 3
- Scan tier: standard · observed 2026-08-20 21:06:17 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
Categories
- phishing
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Domain impersonates steam (combosquat)
- Domain registered 0 day(s) ago
- Certificate issued < 48h ago
Detected technologies
- Cloudflare
Contacted infrastructure
- 185.158.133.1 - AS13335 Internet Utilities Europe and Asia Limited (Poland)
Observed indicators
- geronimomensteambinder.online
- 185.158.133.1
- https://geronimomensteambinder.online/binder
- https://geronimomensteambinder.online/assets/styles-b52GgY1B.css
- https://geronimomensteambinder.online/assets/index-BzOwvX6g.js
- https://geronimomensteambinder.online/assets/rolldown-runtime-QTnfLwEv.js
- https://geronimomensteambinder.online/assets/useStore-D1mDm7_j.js
- https://geronimomensteambinder.online/assets/link-jT7gXasX.js
- https://geronimomensteambinder.online/assets/Match-MkHOf8Fg.js
- https://geronimomensteambinder.online/assets/matchContext-bckAriCf.js
- https://geronimomensteambinder.online/assets/route-CC7MYe9f.js
- https://geronimomensteambinder.online/assets/binder-D-iHvGWL.js
- https://geronimomensteambinder.online/assets/format-CY1QNt9V.js
- https://geronimomensteambinder.online/assets/label-yzLVNiqO.js
- https://geronimomensteambinder.online/assets/ethos-logo-CV8aXrER.js
- https://geronimomensteambinder.online/favicon.png
- https://geronimomensteambinder.online/apple-touch-icon.png
- https://geronimomensteambinder.online/manifest.webmanifest
- https://geronimomensteambinder.online/~flock.js
Questions about geronimomensteambinder.online
- Is geronimomensteambinder.online safe?
- No. MalwareAnalyzer scanned geronimomensteambinder.online on 20 Aug 2026 and returned a malicious verdict with a score of 73 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was geronimomensteambinder.online checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of geronimomensteambinder.online
Scanned on MalwareAnalyzer by Cyble · Open interactive scan