stakingsrewards[.]club
stakingsrewards.club — Контент недоступний (HTTP 502). Уособлення бренду: Fake Staking; Тип шахрайства: Investment Scam. Зведення доказів: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
stakingsrewards.club is a newly registered domain that was created on 21 February 2026. The zone resolves to the Cloudflare‑owned address 104.21.48.150, which is geolocated to Canada and is typical of CDN‑based hosting used by malicious operators. The site was classified as an investment‑scam impersonating the “Fake Staking” brand, indicating a targeted brand‑impersonation campaign aimed at cryptocurrency users. Multiple client‑side extensions have already flagged the domain; PhishDestroy, MetaMask, Polkadot, SEAL, and Enkrypt each block access, suggesting that the payload or credential‑harvesting page is recognized by their threat‑intel feeds.
VirusTotal analysis shows 17 of 93 scanners labeling the domain as malicious, reinforcing the malicious classification. Gridinsoft assigns a trust score of 0 out of 100, and the domain is listed on six public blocklists, further evidencing its reputation as a phishing or scam host. The domain is currently taken offline, which may be the result of takedown actions or temporary hosting changes; however, the underlying infrastructure—Cloudflare IP and the same registration details—remains publicly reachable and could be re‑activated.
Analysts should continue monitoring the IP address 104.21.48.150 for re‑appearance of the domain or related sub‑domains, add the host to internal blocklists, and advise users to avoid any unsolicited communications that reference “Fake Staking” investments. Because the site’s content has not been captured, the precise phishing vector (e.g., login page, malicious download) remains unknown, and threat‑hunting teams should look for associated indicators such as the observed user‑agent strings or request patterns that appeared in the extensions’ block logs. Ongoing vigilance is recommended until the infrastructure is fully dismantled.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога