haedal[.]stakingrewards[.]biz
“Google”
haedal.stakingrewards.biz — Контент недоступний. Уособлення бренду: Google; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 15/93 (ADMINUSLabs, ChainPatrol, BitDefender, CRDF, CyRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of haedal.stakingrewards.biz shows a credential‑phishing infrastructure that directly impersonates Google, as indicated by the page title "Google" and the explicit brand target. The domain was registered on February 21, 2026 and resolves to the IP address 172.253.62.99, which belongs to AS15169 Google LLC located in the United States. This IP association is frequently abused to lend legitimacy to malicious sites. The SSL certificate is identified as type WR2, providing transport‑layer encryption but offering no indication of trustworthiness.
Reputation scoring from Gridinsoft assigns a zero out of one hundred, reflecting a complete lack of trust. VirusTotal scans report that fifteen out of ninety‑three security vendors flag the domain, reinforcing the malicious assessment. Independent blocklists, specifically PhishDestroy and ScamSniffer, have already listed the domain, and it appears on two additional security blocklists. The site’s current status is offline, suggesting that takedown actions may have been applied, yet the infrastructure remains observable and could be re‑activated.
Defenders should immediately add 172.253.62.99 to network‑level deny lists and ensure that any DNS resolution for haedal.stakingrewards.biz is blocked. Logging of TLS handshakes to this IP should be reviewed for any residual traffic. Security appliances that reference reputation feeds must be updated to include the domain and its associated IP, and existing endpoint protection rules should be checked for the fifteen vendor detections reported by VirusTotal. Continuous monitoring of the domain’s registration status is advised, as re‑registration could enable a resurgence of the phishing campaign.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога