wlfi[.]stakingsrewards[.]club
“Google”
wlfi.stakingsrewards.club — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Google; Betrugstyp: Credential Phishing. Zusammenfassung der Beweislage: VirusTotal 16/93 (ChainPatrol, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 95/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain wlfi.stakingsrewards.club was registered on 21 February 2026. DNS resolution points to 142.251.140.164, an address announced by AS15169 Google LLC and geolocated to Germany. Hosting on a Google‑owned IP range is a common tactic for brand‑impersonation campaigns because it can lend perceived legitimacy and evade simple network‑based blocking. The site presented a page title of “Google”, and the threat classification identifies it as a credential‑phishing operation targeting the Google brand.
The SSL certificate associated with the domain is identified as “WE2”, indicating a publicly trusted certificate that further masks malicious intent. VirusTotal analysis shows that 16 out of 93 scanning engines flagged the domain, confirming malicious behavior observed by multiple vendors. The domain appears on a single external blocklist and has been actively blocked by the PhishDestroy service, which specializes in phishing takedown. The current online status is reported as offline, suggesting the payload may have been removed or the operators have temporarily withdrawn the site.
Evidence confirms the use of a legitimate cloud provider, a brand‑matching page title, and a trusted TLS certificate, all of which are consistent with a credential‑phishing campaign. However, the exact content served, the phishing kit employed, and the full list of victim‑targeted URLs remain unknown because the site is no longer reachable. Defenders should continue to block the domain at DNS and proxy layers, monitor for any resurrection of the host, and include the IP address 142.251.140.164 in reputation‑based filtering despite its legitimate ownership. Additional hunting should focus on other subdomains under the same registrar that may share the same hosting pattern, and on any outbound traffic to Google‑related services that could indicate compromised credentials being exfiltrated.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt