stakingsrewards[.]cyou
“Google”
stakingsrewards.cyou — 内容不可用 (HTTP 502). 品牌冒充:Google; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 6/95 (ChainPatrol, alphaMountain.ai, Google Safebrowsing, Gridinsoft, Seclookup); PhishDestroy score 68/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, stakingsrewards.cyou, was registered on 23 November 2025 through Dynadot LLC. The site presented a page title of “Google”, matching the declared brand target. No TLS certificate was observed, indicating that the service operated over plain HTTP. DNS resolution points to 142.250.185.228, an address announced by AS15169, which belongs to Google LLC in the United States. The use of Google‑owned infrastructure for a malicious brand‑impersonation campaign is a notable indicator of infrastructure abuse.
The domain is served by Cloudflare name servers (alexa.ns.cloudflare.com and randall.ns.cloudflare.com), a common choice for fast‑flux or proxying tactics. Reputation scoring from Gridinsoft assigned a trust score of 0 out of 100, reflecting extreme suspicion. VirusTotal analysis recorded six positive detections out of ninety‑five scanners, confirming that multiple security vendors have identified the domain as malicious. The domain appears on one external blocklist and has been actively blocked by the PhishDestroy mitigation service.
The current operational status is offline, suggesting that the hosting has been taken down or the site has been otherwise disabled. Given the observed indicators, defenders should continue to block stakingsrewards.cyou at DNS and proxy layers, monitor for any re‑registration attempts, and consider adding the IP address 142.250.185.228 to watchlists despite its legitimate ownership, as abuse of trusted infrastructure can be leveraged for future campaigns. Analysts should also flag the associated Cloudflare name servers for heightened scrutiny, and update any brand‑specific threat intelligence feeds for Google impersonation to include this recent artifact. Further investigation is required to determine whether additional sub‑domains or related payloads were deployed before takedown.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.cyou
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。