xpl[.]stakingsrewards[.]club
“Google”
xpl.stakingsrewards.club — 内容不可用. 品牌冒充:Google; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 14 detections (engine total unavailable) (ADMINUSLabs, ChainPatrol, BitDefender, CRDF, CyRadar); PhishDestroy score 92/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain xpl.stakingsrewards.club was registered on February 21, 2026 and is currently listed as offline. Infrastructure analysis shows that the domain resolves to the IP address 142.251.140.164, which belongs to AS15169 Google LLC and is geolocated in Germany. The presence of a WE2 SSL certificate indicates that the site was served over HTTPS, but the certificate details have not been disclosed. The page title reported for the site is "Google," matching the declared brand target of Google and confirming the credential‑phishing intent.
The domain appears on a single security blocklist and is specifically blocked by the PhishDestroy filtering service. VirusTotal scans have recorded 14 detections out of 95 security vendors, reinforcing the malicious classification. Although the site is no longer reachable, the historical evidence suggests a short‑lived phishing campaign that leveraged a legitimate‑looking Google brand to harvest credentials.
Defenders should update their DNS and URL filtering policies to block the domain and the associated IP address, monitor for any future registrations that reuse the same sub‑domain pattern, and consider adding the IP to reputation‑based blocklists. Continuous monitoring of threat‑intel feeds for similar Google‑impersonation indicators is recommended, as the underlying infrastructure (Google‑owned IP space) could be reused by other actors. The limited detection footprint (one blocklist entry) does not diminish the risk; the confirmed brand impersonation and multi‑vendor detections warrant an elevated defensive posture until the domain remains offline.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。