ldo[.]stakingsrewards[.]club
“Google”
ldo.stakingsrewards.club — 内容不可用. 品牌冒充:Google; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 17 detections (engine total unavailable) (ADMINUSLabs, ChainPatrol, BitDefender, CRDF, CyRadar); PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain ldo.stakingsrewards.club has been identified as part of a credential theft operation specifically targeting Gmail users. Analysis confirms the domain is designed to impersonate the Gmail login interface, as evidenced by its page title labeled "Google." The infrastructure is currently offline, but prior activity indicates a deliberate attempt to harvest user credentials through brand impersonation. Infrastructure analysis reveals the domain was created on February 21, 2026, and resolves to the IP address 192.178.155.106, hosted under AS15169 (Google LLC) in the United States. Security vendors on VirusTotal flagged the domain, with 17 out of 95 engines detecting malicious activity. The SSL certificate is categorized as WR2, indicating potential weaknesses or misconfiguration. The domain appears on one security blocklist and was previously blocked by a specialized anti-phishing system. Despite its current offline status, the domain’s creation date and hosting details suggest premeditated malicious intent. Organizations and users are advised to treat this domain as a confirmed threat. Network-level blocking of 192.178.155.106 and ldo.stakingsrewards.club is recommended to prevent accidental exposure. Security teams should monitor for similar domains leveraging the "stakingsrewards" subdomain pattern or Google LLC hosting for credential theft campaigns. End-users should be educated on recognizing impersonation attempts, particularly those mimicking login portals for widely used services like Gmail.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。