thq[.]stakingsrewards[.]club
“Google”
thq.stakingsrewards.club — 内容不可用 (HTTP 502). 品牌冒充:Google; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 15/93 (ADMINUSLabs, ChainPatrol, BitDefender, CRDF, CyRadar); PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
On 23 July 2026, analysis of the domain thq.stakingsrewards.club identified it as a credential‑phishing site that impersonates Google. The domain was registered on 21 February 2026 and resolves to the IP address 172.253.63.99, which is owned by AS15169 Google LLC and geolocated in the United States. The TLS certificate presented for the host is identified as “WR2”, and the page title returned by the server is “Google”, matching the declared brand target. VirusTotal records show that 15 of 93 scanning engines flag the domain as malicious, and the site appears on a single external blocklist.
Independent monitoring by PhishDestroy has also listed the domain as blocked. The Gridinsoft trust score is 0 out of 100, indicating a lack of reputation. The site is currently offline, which may be the result of takedown actions or temporary hosting changes. While the available data confirms the presence of a credential‑phishing infrastructure, the specific phishing kit or any additional payloads have not been observed.
Defensive teams should add the domain and its resolved IP address to network‑level deny lists, enforce DNS sink‑holing for the host, and monitor for any rapid re‑registration attempts. Continuous observation of related AS15169 traffic for anomalous request patterns is advised, as well as periodic re‑scanning on VirusTotal and other multi‑engine platforms to capture any changes in detection rates. Organizations using Google services should reinforce multi‑factor authentication and educate users about unsolicited login prompts that reference the “Google” brand. The limited blocklist presence suggests that broader threat‑intel sharing may be beneficial to raise visibility of this campaign.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。