Skip to security report
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 4. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
REGISTRAR NEGLIGENCE · EGREGIOUS URL Solutions, Inc. was notified 4 months ago — the threat is still operational.
Why this matters — ICANN RAA §3.18 obligation & victim-assistance

On PhishDestroy delivered an evidence-backed abuse report (repeated 8 times, most recently ) to abuse@identitydigital.com with the evidence stored for the case at that time. More than 4 months later, the phishing infrastructure remains reachable .

Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.

Victim-assistance obligation. If URL Solutions, Inc. doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 8 separate notifications over 4 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.

Elapsed since first report
4 months
Reports sent
8
Latest case ID
PD-1772792940-1win.pro
Current status
Serving traffic (alive)
أمن المجال وذكاء التهديدات

1win[.]pro

فحص التصيد والأمان للنطاق 1win.pro

“Онлайн Казино и Ставки на Спорт | Официальный сайт 1win”

حكم التهديد حرجة 86/100 درجة الأدلة
التوفر مغطى بعباءة · يمكن الوصول إليه تمت ملاحظة إمكانية الوصول من خلال عمليات فحص إخفاء الهوية
إشارات الخطر
اكتشافات VirusTotal: 4/91 نوع الاحتيال: Gambling آخر نشاط معروف
4/91 VT 06/03/2026 Gambling 8 Reports Sent Cloaking CDN
ملخص التقرير

1win.pro: أظهرت نتيجة VirusTotal أن 4 من أصل 91 محركًا رصد هذا النطاق. راجع DNS وSSL وجهة التسجيل وقوائم الحظر.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Summary
CRITICAL
Ref
7FFBBA3C
Score
86/100
Mode
Evidence v1

PhishDestroy first recorded 1win.pro on Mar 6, 2026. This English evidence brief is rebuilt from the current structured observations stored for the report. The current evidence score, computed from those stored observations, is 86/100.

The latest stored availability state is “Cloaked · reachable” (HTTP 403) on Aug 3, 2026 at 01:18 UTC. This is a reachability snapshot, not proof of the cause of any outage, restriction, or status change.

VirusTotal returned 4 detections from 91 scanners in the stored check on Jul 19, 2026 at 02:00 UTC. No completed independent-blocklist snapshot is stored. PhishDestroy's own listing is not counted as an independent match.

Other stored evidence. Google Safe Browsing stored no positive flag on Mar 6, 2026 at 12:29 UTC. This time-bound result is not evidence of safety. AlienVault OTX stored 0 pulse references on Mar 6, 2026 at 12:29 UTC. OTX pulses are community-intelligence references, not vendor verdicts. The Spamhaus DBL snapshot stored no positive result on Jul 14, 2026 at 02:32 UTC. That result is not evidence of safety. A URLScan capture is stored from Mar 24, 2026 at 11:51 UTC.

Stored context lists registrar URL Solutions, Inc., IP address 194.67.193.51, registration date Mar 6, 2026. Except for the registration date, these fields do not share a source timestamp in this report and may change.

Treat these as stored, time-bound observations rather than a live safety guarantee. Source verdicts and reachability can change, and zero or missing vendor matches never prove that a domain is safe. Avoid interacting with the domain while uncertainty remains, and use the appeal process if this report is inaccurate.

VirusTotal
VirusTotal
4 det.
Gridinsoft
39/100
شهادة TLS
منتهية الصلاحية أو غير متحقق منها
العمر
5 mo
الحالة المرصودة
مغطى بعباءة · يمكن الوصول إليه 403
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
8 ignored
نطاق تغطية البيانات VirusTotal 4 / 91 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق OTX no community references رادار CF no data URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 5 mo old Screenshot لقطة خارجية سلسلة إعادة التوجيه لم يتم التحقيق فيها Gridinsoft 39/100
مؤشرات الأمان
GS Gridinsoft Analysis 39 / 100
'', 1/27 Suspicious Website 1win.pro 21 AM 41 PM Airtable Blacklisted Clean

مسار الاستجابة للتهديدات Pipeline

Discovery
Checks
Reports
التوفر
21/22
Initial Abuse Report (#1)
Sent to 1 abuse contact at URL Solutions, Inc. with forensic evidence
abuse@identitydigital.com
06/03/2026
ICANN Escalation #2
Escalation #2 sent to 2 recipients including ICANN Compliance — follow-up record after a previous report
abuse@identitydigital.comcompliance@icann.org
09/04/2026
ICANN Escalation #3
Escalation #3 sent to 2 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@identitydigital.comcompliance@icann.org
22/04/2026
ICANN Escalation #4
Escalation #4 sent to 2 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@identitydigital.comcompliance@icann.org
24/04/2026
ICANN Escalation #5
Escalation #5 sent to 2 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@identitydigital.comcompliance@icann.org
26/04/2026
ICANN Escalation #6
Escalation #6 sent to 2 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@identitydigital.comcompliance@icann.org
28/04/2026
ICANN Escalation #7
Escalation #7 sent to 2 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@identitydigital.comcompliance@icann.org
02/05/2026
ICANN Escalation #8
Escalation #8 sent to 2 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@identitydigital.comcompliance@icann.org
07/05/2026
8 Reports Filed
8 report records were stored over 149 days; current observed status: مغطى بعباءة · يمكن الوصول إليه

حالة قوائم الحظر العامة

Stored Capture

عنوان الصفحة
Онлайн Казино и Ставки на Спорт | Официальный сайт 1win
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن WE1

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN cloudflare · AS211072 MFI-AS MFI INVESTMENTS LIMITED, CY
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق URL Solutions US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@urlsolutions.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ 1win.pro →
عنوان IP 194.67.193.51 CDN
الموقع الجغرافيDE Frankfurt am Main, DE
الشبكةAS211072 · MFI INVESTMENTS LIMITED
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 06/03/2026 (149d)
حالة HTTP403 Forbidden
CloakingCloaking Detected Status split · score 1/6
This site shows different content to security bots vs real users
Elapsed Since First Report 7 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: مغطى بعباءة · يمكن الوصول إليه.
Minimum notice count 8 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف06/03/2026
خوادم الأسماءpranab.ns.cloudflare.com
Favicon Hash
Case ID
ICANN OVERSIGHT

الاعتماد وسياق RAA

حصلت ICANN على أموالها. أما المساءلة فلم تصل.

بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.

الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.

ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.

ملاحظة ساخرة عن المساءلة لا يُرسل أي شيء تلقائياً.
سجل بلاغات إساءة الاستخدام · 8 stored reports over 62 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
8 abuse reports filed over 149 days — latest observed status: مغطى بعباءة · يمكن الوصول إليه
The records name URL Solutions, Inc. as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
8
reports
149
days
ICANN CC
  1. Report #1 Mar 6, 2026 · 10:29 UTC
    Phishing Abuse Report: 1win[.]pro
    abuse@identitydigital.com
  2. Report #2 ICANN CC 813h still active Apr 9, 2026 · 11:17 UTC
    ESCALATION #2 (813h active): Phishing - 1win[.]pro
    abuse@identitydigital.com compliance@icann.org
  3. Report #3 ICANN CC 1136h still active Apr 22, 2026 · 22:04 UTC
    ESCALATION #3 (1136h active): Phishing - 1win[.]pro
    abuse@identitydigital.com compliance@icann.org
  4. Report #4 ICANN CC 1182h still active Apr 24, 2026 · 20:06 UTC
    ESCALATION #4 (1182h active): Phishing - 1win[.]pro
    abuse@identitydigital.com compliance@icann.org
  5. Report #5 ICANN CC 1227h still active Apr 26, 2026 · 17:11 UTC
    ESCALATION #5 (1227h active): Phishing - 1win[.]pro
    abuse@identitydigital.com compliance@icann.org
  6. Report #6 ICANN CC 1276h still active Apr 28, 2026 · 18:01 UTC
    ESCALATION #6 (1276h active): Phishing - 1win[.]pro
    abuse@identitydigital.com compliance@icann.org
  7. Report #7 ICANN CC 1374h still active May 2, 2026 · 19:36 UTC
    ESCALATION #7 (1374h active): Phishing - 1win[.]pro
    abuse@identitydigital.com compliance@icann.org
  8. Report #8 ICANN CC 1476h still active May 7, 2026 · 01:51 UTC
    ESCALATION #8 (1476h active): Phishing - 1win[.]pro
    abuse@identitydigital.com compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

4 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Chong Lua Dao
CRDF
Forcepoint ThreatSeeker
Gridinsoft

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

أنت لست وحدك، ولا يوجد ما يدعو للخجل. المحتالون هم مجرمون ماهرون يستغلون ثقة الناس. ويُعد الإبلاغ عن تجربتك أقوى سلاح لمكافحة الاحتيال — فإبلاغك هذا يمكن أن يمنع وقوع ضحايا جدد ويساعد سلطات إنفاذ القانون على اتخاذ الإجراءات اللازمة. الصمت هو أكبر ميزة للمحتال. حطّمه.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

Europol
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

حول هذا التقرير: 1win.pro

يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.

عرض الموقع الذي تم التقاطه عنوان الصفحة “Онлайн Казино и Ставки на Спорт | Официальный сайт 1win”.

اعتبارًا من 03/08/2026، كان لدى 1win.pro اكتشافات من محركات الأمان 4.

إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/1win.pro"
  title="PhishDestroy threat report for 1win.pro"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.