plume[.]stakingsreward[.]art
“Google”
plume.stakingsreward.art — İçerik kullanılamıyor. Marka kimliğine bürünme: Google; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
plume.stakingsreward.art is a newly registered domain (created 21 February 2026) that has been identified as a credential‑phishing site targeting Google users. The domain resolves to the IP address 142.251.141.68, which is owned by Google LLC (AS15169) and geolocated in Germany. The use of a legitimate Google‑owned IP range is a common tactic to lend credibility to malicious pages. The TLS certificate associated with the domain is identified as “WE2”, indicating that HTTPS is available, but the site has been taken offline as of the report date.
The page title returned by the server is simply “Google”, matching the declared brand target. Threat intelligence sources have assigned the domain a Gridinsoft trust score of 0 / 100 and it appears on one security blocklist. PhishDestroy has actively blocked the domain, and VirusTotal records show that 13 of 95 scanning engines flag the domain as malicious. The classification aligns with a credential‑phishing campaign, although no payload samples or page screenshots have been published, leaving the exact phishing flow unverified.
Defenders should continue to block the domain at the network perimeter, add the IP address 142.251.141.68 to internal deny lists when associated with suspicious traffic, and monitor for any resurgence of the domain or similar sub‑domains that reuse the same SSL certificate or page title. Ongoing observation of the AS15169 range for anomalous request patterns is recommended, as abuse of legitimate cloud infrastructure can bypass many perimeter controls. Incident response teams should treat any login attempts to Google services originating from this domain as compromised and advise affected users to reset credentials immediately.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin