stake3[.]us
“STAKE3 | Play at the best online casino based on Blockchain”
stake3.us — 未验证. 品牌冒充:Cryptoscam; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 4/95 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; PhishDestroy score 65/100. 注册商: Web Commerce Communica….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Stake3.us was observed hosting a cryptocurrency draining site that presented itself as an online casino leveraging blockchain technology, as indicated by the page title “STAKE3 | Play at the best online casino based on Blockchain”. The domain was registered on July 14, 2025 through Web Commerce Communications Limited and resolves to the IPv4 address 69.5.189.54, which is allocated to AS42624 Global-Data System IT Corporation in Switzerland. The hosting infrastructure is served by four nameservers (ns1.nameserverhub.com, ns2.nameserverhub.com, ns3.nameserverhub.com, ns4.nameserver), and no TLS certificate was present at the time of analysis, leaving the site accessible only over HTTP. The site was identified as using the “Gambler Scam” phishing kit, a known template for crypto‑related frauds that typically harvest wallet credentials or trick victims into sending funds. Detection platforms have flagged the domain: four of ninety‑five VirusTotal scanners raised alerts, and the domain appears on one external blocklist.
The Gridinsoft trust score is 0 out of 100, and the domain has been blocked by the PhishDestroy mitigation service. The current HTTP status is offline, but the underlying IP and name server configuration remain active. Defenders should treat stake3.us as a confirmed crypto‑drainer threat. Immediate actions include adding the IP address 69.5.189.54 to network deny lists, enforcing DNS sink‑hole rules for the four associated nameservers, and ensuring that any outbound connections to the domain are blocked at the firewall level.
Because the domain lacks SSL, any attempted HTTP requests can be intercepted and logged for threat‑intel enrichment. Continuous monitoring of the AS42624 block for new sub‑domains or similar registrations is advised, as the operator may repurpose the infrastructure under a different domain. Updating endpoint and web‑gateway filters with the observed VirusTotal signatures and the “Gambler Scam” kit indicators will reduce exposure.
威胁响应 Pipeline
公共封禁名单状态
Casino / Gambling License Verification
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。