www.wonsteam.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.wonsteam.com and returned a suspicious verdict (score 33), categorised as phishing. The page resolved to 27.0.236.142 on DREAMLINE CO. in KR. The domain was registered 71 days ago through Megazone Corp., dba HOSTING.KR. 7 domains and 1 IP were contacted, over 27 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 33) · Confidence 39%
- Scanned URL:
https://www.wonsteam.com/ - Domain: www.wonsteam.com · IP: 27.0.236.142 · AS7625 · KR
- Page title: 원스팀
- HTTP status: 200 · text/html;charset=UTF-8
- Registrar: Megazone Corp., dba HOSTING.KR · domain age 71 days · created 2026-06-10
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 17 22: · subject CN=www.wonsteam.com
- HTTP requests captured: 27
- Scan tier: standard · observed 2026-08-20 22:30:15 UTC
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Domain impersonates steam (combosquat)
- Certificate issued < 48h ago
Detected technologies
- jQuery
Observed indicators
- www.wonsteam.com
- tistory1.daumcdn.net
- t1.daumcdn.net
- developers.kakao.com
- wonsteam.tistory.com
- search1.daumcdn.net
- cdnjs.cloudflare.com
- 27.0.236.142
- https://www.wonsteam.com/
- https://tistory1.daumcdn.net/tistory_admin/userblog/userblog-d748cfd5e0a0f73a4f05afc297a1e4fc6364eea5/static/plugin/BusinessLicenseInfo/style.css
- https://tistory1.daumcdn.net/tistory_admin/userblog/userblog-d748cfd5e0a0f73a4f05afc297a1e4fc6364eea5/static/plugin/TistoryProfileLayer/style.css
- https://tistory1.daumcdn.net/tistory_admin/userblog/userblog-d748cfd5e0a0f73a4f05afc297a1e4fc6364eea5/static/plugin/TistoryProfileLayer/script.js
- https://t1.daumcdn.net/tistory_admin/lib/jquery/jquery-3.5.1.min.js
- https://t1.daumcdn.net/tiara/js/v1/tiara-1.2.0.min.js
- https://tistory1.daumcdn.net/tistory_admin/userblog/userblog-d748cfd5e0a0f73a4f05afc297a1e4fc6364eea5/static/pc/dist/index.js
- https://tistory1.daumcdn.net/tistory_admin/userblog/userblog-d748cfd5e0a0f73a4f05afc297a1e4fc6364eea5/static/pc/dist/index-legacy.js
- https://tistory1.daumcdn.net/tistory_admin/userblog/userblog-d748cfd5e0a0f73a4f05afc297a1e4fc6364eea5/static/pc/dist/polyfills-legacy.js
- https://t1.daumcdn.net/tistory_admin/favicon/tistory_favicon_32x32.ico
- https://t1.daumcdn.net/tistory_admin/top_v2/bi-tistory-favicon.svg
- https://t1.daumcdn.net/tistory_admin/top_v2/tistory-apple-touch-favicon.png
Questions about www.wonsteam.com
- Is www.wonsteam.com safe?
- No. MalwareAnalyzer scanned www.wonsteam.com on 20 Aug 2026 and returned a suspicious verdict with a score of 33 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was www.wonsteam.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.wonsteam.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan