steamcommunity.com - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned steamcommunity.com and returned a benign verdict (score 0). The page resolved to 23.221.132.220 on Akamai Technologies, Inc. in AU. 10 domains and 3 IPs were contacted, over 166 HTTP requests. 4 malware samples communicate with this URL (Lumma, Clipbanker, HUILoader). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 34%
- Scanned URL:
https://steamcommunity.com/id/luzegra - Domain: steamcommunity.com · IP: 23.221.132.220 · AS16625 · AU
- Server: nginx
- Page title: Steam Community :: Luzegra
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 12 22: · subject CN=steamcommunity.com
- HTTP requests captured: 166 · cookies set: 3 · outgoing links: 220
- Scan tier: standard · observed 2026-08-20 16:02:15 UTC
Malware communicating with this URL (4)
These samples were observed contacting or being served from steamcommunity.com. Each links to its full analysis.
- Lumma - contacted ·
002f714f93bed53f165129a820c2d5b7· first seen 2026-08-19 - Clipbanker - referenced ·
ac0ef032165f08ebf92702b3c401b801· first seen 2026-08-15 - HUILoader - referenced ·
59865cc49604fe2eed1886a5e0611304· first seen 2026-08-13 - 3fed685e1b41d37f28a2fbd69ee3755ab4797b5d9b60ca6d904b2c9529af12f8.exe - contacted ·
3fed685e1b41d37f28a2fbd69ee3755a· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- jQuery
Contacted infrastructure
- 23.221.132.220 - AS16625 Akamai Technologies, Inc. (Australia)
- 151.101.31.52 - AS54113 Fastly, Inc. (Australia)
- 199.232.139.52 - AS54113 Fastly, Inc. (Australia)
Observed indicators
- steamcommunity.com
- community.akamai.steamstatic.com
- avatars.akamai.steamstatic.com
- store.steampowered.com
- help.steampowered.com
- www.valvesoftware.com
- shared.akamai.steamstatic.com
- community.fastly.steamstatic.com
- shared.fastly.steamstatic.com
- avatars.fastly.steamstatic.com
- 23.221.132.220
- 151.101.31.52
- 199.232.139.52
- https://steamcommunity.com/id/luzegra
- https://steamcommunity.com/favicon.ico
- https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=G517uopaUy8x&l=english&_cdn=akamai
- https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=WgcGW2rjIiQ0&l=english&_cdn=akamai
- https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=XIYptIOlpBWN&l=english&_cdn=akamai
- https://community.akamai.steamstatic.com/public/css/globalv2.css?v=dRiOMTaO1-6B&l=english&_cdn=akamai
- https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=WXAusLHclDIt&l=english&_cdn=akamai
Other scans of steamcommunity.com (9)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - suspicious ·
https://connect.steamlevelu.com/ - 22 Aug 2026 - unknown ·
https://www.pcgamer.com/mod-of-the-week-helgen-reborn-for-skyrim/ - 21 Aug 2026 - unknown ·
https://steam.synergy.tf/ - 21 Aug 2026 - suspicious ·
https://steam-gifts.ir/ - 21 Aug 2026 - malicious ·
https://prod.admin.steamlevelu.com/ - 20 Aug 2026 - malicious ·
https://staging.dashboard.steamlevelu.com/ - 19 Aug 2026 - benign ·
https://steamcommunity.com/ - 12 Aug 2026 - benign ·
https://steamcommunity.com/ - 24 Jul 2026 - unknown ·
https://store.communityuserstudion.shop/workshop/AWP-AncientHeritage/
Questions about steamcommunity.com
- Is steamcommunity.com safe?
- The scan of steamcommunity.com on 20 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with steamcommunity.com?
- 4 analysed samples communicate with this URL, including Lumma, Clipbanker, HUILoader.
- How was steamcommunity.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of steamcommunity.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan