w[.]stakingrewards[.]biz
“Google”
w.stakingrewards.biz — 内容不可用 (HTTP 502). 品牌冒充:Google; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 16/93 (ADMINUSLabs, ChainPatrol, BitDefender, CRDF, CyRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of w.stakingrewards.biz, observed on July 23 2026, indicates an active credential‑phishing campaign targeting Google users. The domain was registered on 21 February 2026 and is currently taken offline. Infrastructure data show the hostname resolves to 142.251.163.106, an address owned by Google LLC (AS15169) located in the United States. Despite the legitimate‑looking IP ownership, the domain is listed on two security blocklists and has been blocked by the PhishDestroy and ScamSniffer services.
The site presented a page title of “Google”, matching the declared brand target, and the SSL certificate identifier is reported as “WR2”. Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, indicating a high confidence of malicious intent. VirusTotal scans returned 16 positive detections out of 93 submitted engines, reinforcing the malicious classification. The campaign’s primary objective is credential harvesting, as indicated by the “Credential Phishing” label.
At present, no additional artifacts such as malware payloads or command‑and‑control endpoints have been disclosed, and the exact phishing page content remains unverified. Defenders should continue to enforce blocklist rules for w.stakingrewards.biz, monitor for any resurgence of the domain, and apply URL filtering that flags the domain for Google‑related credential requests. Network traffic to the associated IP should be reviewed for anomalous authentication attempts, and endpoint protection should be configured to honor the 16 VirusTotal detections. Ongoing intelligence collection is recommended to capture any future hosting changes or re‑registration attempts.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。