info.steamsaunabath.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned info.steamsaunabath.com and returned a suspicious verdict (score 33), categorised as phishing. The page resolved to 104.21.41.113 on Cloudflare, Inc. in US. 19 domains and 11 IPs were contacted, over 37 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 33) · Confidence 39%
- Scanned URL:
https://info.steamsaunabath.com/ - Domain: info.steamsaunabath.com · IP: 104.21.41.113 · AS13335 · US
- Server: cloudflare
- HTTP status: 404 · text/html
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 17 23: · subject CN=0844a27c.sni.cloudflaressl.com
- HTTP requests captured: 37 · cookies set: 15 · outgoing links: 153
- Scan tier: standard · observed 2026-08-20 23:52:10 UTC
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Domain impersonates steam (combosquat)
- Certificate issued < 48h ago
Detected technologies
- Cloudflare
- Google Analytics
- jQuery
Contacted infrastructure
- 104.21.41.113 - AS13335 Cloudflare, Inc. (United States)
- 142.250.195.234 - AS15169 Google LLC (India)
- 142.250.195.131 - AS15169 Google LLC (India)
- 216.239.32.178 - AS15169 Google LLC (United States)
Observed indicators
- info.steamsaunabath.com
- 7052064.fs1.hubspotusercontent-na1.net
- steamsaunabath-prod.dbridgesolutions.com
- http
- www.pinterest.com
- www.facebook.com
- www.twitter.com
- www.instagram.com
- fonts.googleapis.com
- cdn2.hubspot.net
- fonts.gstatic.com
- js.hs-analytics.net
- js.hubspot.com
- js.hs-banner.com
- app.hubspot.com
- www.google-analytics.com
- cta-service-cms2.hubspot.com
- perf-na1.hsforms.com
- track.hubspot.com
- 104.21.41.113
Questions about info.steamsaunabath.com
- Is info.steamsaunabath.com safe?
- No. MalwareAnalyzer scanned info.steamsaunabath.com on 20 Aug 2026 and returned a suspicious verdict with a score of 33 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was info.steamsaunabath.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of info.steamsaunabath.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan