blue[.]stakingsreward[.]org
“Google”
blue.stakingsreward.org — المحتوى غير متوفر. انتحال العلامة التجارية: Google; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 15/93 (ADMINUSLabs, ChainPatrol, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 95/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, blue.stakingsreward.org, was observed targeting the Google brand through a classic brand‑impersonation technique. The domain was registered through Dynadot LLC on 27 December 2025 and resolves to the IP address 142.251.32.100, which belongs to AS15169 owned by Google LLC and is located in the United States. The hosting infrastructure therefore appears to be co‑located with legitimate Google services, a tactic often used to increase credibility. DNS resolution is served by Cloudflare name servers alexa.ns.cloudflare.com and randall.ns.cloudflare.com, suggesting the operator is leveraging Cloudflare’s CDN and DNS protection. No TLS certificate was presented for the site, indicating the service was delivered over plain HTTP.
The page title returned by the HTTP response is simply “Google”, matching the declared brand target. Google Safe Browsing has flagged the domain for social engineering, and the Gridinsoft trust score is 0 / 100, reflecting a lack of trustworthiness. The domain appears on a single security blocklist and has been listed by PhishDestroy, confirming that at least one external sinkhole has taken action against it. VirusTotal analysis shows that 15 of 93 scanning engines returned a positive detection, reinforcing the malicious classification. The evidence set does not include any payload samples, login page screenshots, or observed credential‑harvesting behavior, so the exact phishing vector remains unclear.
However, the convergence of a brand‑specific page title, a zero‑trust score, Safe Browsing social‑engineering flag, and multiple vendor detections provides sufficient confidence to label the site as a high‑risk brand‑impersonation campaign. Defenders should block the domain at DNS and web‑filter layers, monitor for any traffic to the associated IP address, and enforce HTTPS‑only policies to prevent downgrade attacks.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: stakingsreward.org
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain stakingsreward.org behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب