avt[.]stakingsrewards[.]club
“Google”
avt.stakingsrewards.club — Contenido no disponible. Suplantación de marca: Google; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 17/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 95/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain is flagged as an elevated-risk brand impersonation threat specifically targeting Gmail users. Analysis indicates the infrastructure was designed to mimic legitimate Google login portals, likely aiming to harvest credentials or distribute malicious payloads under the guise of trusted branding. The threat type aligns with patterns observed in credential phishing campaigns, where attackers replicate authentication interfaces to deceive users into disclosing sensitive information. Infrastructure analysis reveals multiple technical indicators corroborating malicious intent. The domain avt.stakingsrewards.club was registered on February 21, 2026, through an undisclosed registrar, a common tactic to obscure ownership. It resolved to the IP address 142.250.185.68, geolocated to the United States under AS15169 (Google LLC), though this IP association appears anomalous given the domain's fraudulent nature. Security vendors on VirusTotal flagged the domain with 17 detections out of 95 scans, indicating moderate consensus on its malicious classification. The domain appears on one security blocklist and was previously blocked by PhishDestroy. The SSL certificate, identified as WE2, lacks transparency and does not align with standard issuance practices for legitimate services. The page title, 'Google,' further confirms the intent to impersonate Gmail's branding. Mitigation steps for this threat type should prioritize credential security and infrastructure hardening. Organizations should immediately block the domain and its associated IP at the network perimeter to prevent access. Users who may have interacted with the domain should be instructed to reset their Gmail passwords using multi-factor authentication and review account activity for unauthorized access. Security teams should monitor for indicators of compromise, including the domain, IP, and SSL certificate fingerprint, across logs and endpoint detection systems. Given the domain's current offline status, continuous monitoring is advised to detect potential re-emergence under a similar or altered infrastructure. Registrars and hosting providers should be notified to facilitate takedown procedures, and affected users should be educated on recognizing brand impersonation tactics, such as scrutinizing domain names and verifying SSL certificate details before entering credentials.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.