Перейти до звіту про безпеку
Checked 09.08.2026 Ref D854EFAF

MALICIOUS — CRITICAL

plasmalabs[.]us

2 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 200.

88/100 evidence score · Critical
VirusTotal
2/91
Blocklists
2 · MetaMask, SEAL
Доступність
Останній відомий активний · HTTP 200
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 2. Публічні списки блокувань, які повідомляють про збіг: 2. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Jump to section
Огляд звіту

plasmalabs.us — Останній відомий активний (HTTP 200). Зведення доказів: VirusTotal 2/91 (ChainPatrol, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 88/100.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Evidence Digest

Ref D854EFAF

plasmalabs.us is classified critical with an evidence score of 88/100. 2 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 30 Apr 2026, hosted on 13.248.213.45 (Amazon.com, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 200.

Stored generated summary (templated)cerebras · 12.07.2026

Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.

Analysis indicates that the domain plasmalabs.us is actively serving web content over HTTPS with a valid GoDaddy DV certificate. The site resolves to the IPv4 address 13.248.213.45, which is hosted in the AWS Global Accelerator network in the United States (California). The domain was registered on 30 April 2026, and an HTTP GET request returns a 200 status code, confirming that the hosting infrastructure is operational. VirusTotal scans have identified the domain as malicious in three out of ninety‑five vendor engines, and Gridinsoft assigns a trust score of zero out of one hundred, reflecting a high confidence of abuse. AlienVault OTX records the domain in eight distinct threat‑intel pulses, and it appears on three public blocklists. The domain is currently blocked by multiple sink‑hole services, including PhishDestroy, MetaMask, and SEAL, reinforcing the view that it is being used for fraudulent activity. The specific brand or service being spoofed by plasmalabs.us has not been disclosed in the available intelligence, leaving the precise lure unknown. However, the generic phishing classification, combined with the rapid registration date and the use of a reputable TLS certificate, matches a pattern observed in recent phishing campaigns that leverage newly registered domains to gain user trust. Defenders should add 13.248.213.45 and plasmalabs.us to deny‑list configurations, enforce strict URL filtering, and monitor for TLS handshakes that present the GoDaddy DV certificate chain. Network traffic to the AWS Global Accelerator edge should be logged, and any credential submission attempts to the domain should be flagged for investigation. Continuous threat‑intel feeds should be consulted for updates on associated payloads or compromised accounts linked to this infrastructure.

VirusTotal
VirusTotal
2 det.
OTX references
Сертифікат TLS
GoDaddy.com / GoDaddy TLS Intermediate CA DV - R1v1
Вік
3 mo
Зафіксований статус
Останній відомий активний 200
PhishDestroy
DestroyList
У списку
Обсяг даних12 recorded checks
VirusTotal 2 / 91 URLQuery не перевірено PhishStats не перевірено OTX 8 community references CF Radar no data URLScan capture not submitted URLScan verdict висновок недоступний Блокування DNS не перевірено TLS valid certificate, 167d WHOIS 3 mo old Знімок екрана не зафіксовано Ланцюжок перенаправлень не досліджено

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
7/9

Статус у публічних блоклистах

Аналітика доменів

Домен
Сервер / ASN AS16509 Amazon.com, Inc.
Репутація IP abuse score 0/100 2 reports checked 12.07.2026
IP-адреса 13.248.213.45 CA
ГеолокаціяCA Montreal, CA
МережаAS16509 · AWS Global Accelerator (GLOBAL)
Зворотний пошук IPviewdns.info → rapiddns.io →
РеєстраціяСтворено 30.04.2026 (101d)
Статус HTTP200
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено15.06.2026
TLS Fingerprint
TLS Observationvalid from 10.07.2026scanned 12.07.2026
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

2 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed
ChainPatrol
Gridinsoft
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно
Вбудувати цей звітRead-only HTML widget
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/plasmalabs.us"
  title="PhishDestroy threat report for plasmalabs.us"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>