plasmalabs[.]us
Resumo das evidências
Analysis indicates that the domain plasmalabs.us is actively serving web content over HTTPS with a valid GoDaddy DV certificate. The site resolves to the IPv4 address 13.248.213.45, which is hosted in the AWS Global Accelerator network in the United States (California). The domain was registered on 30 April 2026, and an HTTP GET request returns a 200 status code, confirming that the hosting infrastructure is operational. VirusTotal scans have identified the domain as malicious in three out of ninety‑five vendor engines, and Gridinsoft assigns a trust score of zero out of one hundred, reflecting a high confidence of abuse. AlienVault OTX records the domain in eight distinct threat‑intel pulses, and it appears on three public blocklists. The domain is currently blocked by multiple sink‑hole services, including PhishDestroy, MetaMask, and SEAL, reinforcing the view that it is being used for fraudulent activity. The specific brand or service being spoofed by plasmalabs.us has not been disclosed in the available intelligence, leaving the precise lure unknown. However, the generic phishing classification, combined with the rapid registration date and the use of a reputable TLS certificate, matches a pattern observed in recent phishing campaigns that leverage newly registered domains to gain user trust. Defenders should add 13.248.213.45 and plasmalabs.us to deny‑list configurations, enforce strict URL filtering, and monitor for TLS handshakes that present the GoDaddy DV certificate chain. Network traffic to the AWS Global Accelerator edge should be logged, and any credential submission attempts to the domain should be flagged for investigation. Continuous threat‑intel feeds should be consulted for updates on associated payloads or compromised accounts linked to this infrastructure.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo