avt[.]stakingsrewards[.]club
“Google”
avt.stakingsrewards.club — Contenu indisponible. Usurpation de l'identité de la marque : Google; Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 17/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 95/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged as an elevated-risk brand impersonation threat specifically targeting Gmail users. Analysis indicates the infrastructure was designed to mimic legitimate Google login portals, likely aiming to harvest credentials or distribute malicious payloads under the guise of trusted branding. The threat type aligns with patterns observed in credential phishing campaigns, where attackers replicate authentication interfaces to deceive users into disclosing sensitive information. Infrastructure analysis reveals multiple technical indicators corroborating malicious intent. The domain avt.stakingsrewards.club was registered on February 21, 2026, through an undisclosed registrar, a common tactic to obscure ownership. It resolved to the IP address 142.250.185.68, geolocated to the United States under AS15169 (Google LLC), though this IP association appears anomalous given the domain's fraudulent nature. Security vendors on VirusTotal flagged the domain with 17 detections out of 95 scans, indicating moderate consensus on its malicious classification. The domain appears on one security blocklist and was previously blocked by PhishDestroy. The SSL certificate, identified as WE2, lacks transparency and does not align with standard issuance practices for legitimate services. The page title, 'Google,' further confirms the intent to impersonate Gmail's branding. Mitigation steps for this threat type should prioritize credential security and infrastructure hardening. Organizations should immediately block the domain and its associated IP at the network perimeter to prevent access. Users who may have interacted with the domain should be instructed to reset their Gmail passwords using multi-factor authentication and review account activity for unauthorized access. Security teams should monitor for indicators of compromise, including the domain, IP, and SSL certificate fingerprint, across logs and endpoint detection systems. Given the domain's current offline status, continuous monitoring is advised to detect potential re-emergence under a similar or altered infrastructure. Registrars and hosting providers should be notified to facilitate takedown procedures, and affected users should be educated on recognizing brand impersonation tactics, such as scrutinizing domain names and verifying SSL certificate details before entering credentials.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif