avt[.]stakingsrewards[.]club
“Google”
avt.stakingsrewards.club — Contenuto non disponibile. Simulazione del marchio: Google; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 17/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 95/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain is flagged as an elevated-risk brand impersonation threat specifically targeting Gmail users. Analysis indicates the infrastructure was designed to mimic legitimate Google login portals, likely aiming to harvest credentials or distribute malicious payloads under the guise of trusted branding. The threat type aligns with patterns observed in credential phishing campaigns, where attackers replicate authentication interfaces to deceive users into disclosing sensitive information. Infrastructure analysis reveals multiple technical indicators corroborating malicious intent. The domain avt.stakingsrewards.club was registered on February 21, 2026, through an undisclosed registrar, a common tactic to obscure ownership. It resolved to the IP address 142.250.185.68, geolocated to the United States under AS15169 (Google LLC), though this IP association appears anomalous given the domain's fraudulent nature. Security vendors on VirusTotal flagged the domain with 17 detections out of 95 scans, indicating moderate consensus on its malicious classification. The domain appears on one security blocklist and was previously blocked by PhishDestroy. The SSL certificate, identified as WE2, lacks transparency and does not align with standard issuance practices for legitimate services. The page title, 'Google,' further confirms the intent to impersonate Gmail's branding. Mitigation steps for this threat type should prioritize credential security and infrastructure hardening. Organizations should immediately block the domain and its associated IP at the network perimeter to prevent access. Users who may have interacted with the domain should be instructed to reset their Gmail passwords using multi-factor authentication and review account activity for unauthorized access. Security teams should monitor for indicators of compromise, including the domain, IP, and SSL certificate fingerprint, across logs and endpoint detection systems. Given the domain's current offline status, continuous monitoring is advised to detect potential re-emergence under a similar or altered infrastructure. Registrars and hosting providers should be notified to facilitate takedown procedures, and affected users should be educated on recognizing brand impersonation tactics, such as scrutinizing domain names and verifying SSL certificate details before entering credentials.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Informazioni forensi
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo