plume[.]stakingsreward[.]art
“Google”
plume.stakingsreward.art — Контент недоступний. Уособлення бренду: Google; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
plume.stakingsreward.art is a newly registered domain (created 21 February 2026) that has been identified as a credential‑phishing site targeting Google users. The domain resolves to the IP address 142.251.141.68, which is owned by Google LLC (AS15169) and geolocated in Germany. The use of a legitimate Google‑owned IP range is a common tactic to lend credibility to malicious pages. The TLS certificate associated with the domain is identified as “WE2”, indicating that HTTPS is available, but the site has been taken offline as of the report date.
The page title returned by the server is simply “Google”, matching the declared brand target. Threat intelligence sources have assigned the domain a Gridinsoft trust score of 0 / 100 and it appears on one security blocklist. PhishDestroy has actively blocked the domain, and VirusTotal records show that 13 of 95 scanning engines flag the domain as malicious. The classification aligns with a credential‑phishing campaign, although no payload samples or page screenshots have been published, leaving the exact phishing flow unverified.
Defenders should continue to block the domain at the network perimeter, add the IP address 142.251.141.68 to internal deny lists when associated with suspicious traffic, and monitor for any resurgence of the domain or similar sub‑domains that reuse the same SSL certificate or page title. Ongoing observation of the AS15169 range for anomalous request patterns is recommended, as abuse of legitimate cloud infrastructure can bypass many perimeter controls. Incident response teams should treat any login attempts to Google services originating from this domain as compromised and advise affected users to reset credentials immediately.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога