nezcas[.]com
فحص التصيد والأمان للنطاق nezcas.com
“Nezcas: Most Popular Online Crypto Casino Based on Blockchain”
nezcas.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Genericcrypto; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 12/93 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 95/100. مسجّل النطاق: MAT BAO.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, nezcas.com, was registered on 10 December 2025 through MAT BAO CORPORATION and is currently taken offline. The site presented a page titled "Nezcas: Most Popular Online Crypto Casino Based on Blockchain," indicating a crypto‑casino theme. Analysis of the hosting shows the domain resolves to 172.67.153.126, an address owned by Cloudflare, Inc. (AS13335) and located in the United States. The authoritative name servers are karsyn.ns.cloudflare.com and phil.ns.cloudflare.com, and no TLS certificate was observed, meaning the site operated without HTTPS. Threat intelligence flags the domain as a crypto scam employing a Gambler Scam phishing kit; the Gridinsoft trust score of 1 out of 100 corroborates a high likelihood of malicious intent.
Twelve of ninety‑three VirusTotal scanners raised detections, and the domain appears on a single external blocklist. PhishDestroy has already blocked the host, confirming active mitigation by at least one anti‑phishing service. While the site is offline, the infrastructure details remain reusable for future campaigns, especially the Cloudflare edge IP and the registrar details. Defenders should continue to monitor the IP 172.67.153.126 for any re‑use in related malicious activities and add the domain and its IP to internal blocklists.
Given the absence of SSL, any future resurrection would likely again lack encryption, providing an additional indicator for detection. Security teams should also watch for the specific page title string and the "Gambler Scam" kit signature in traffic inspection tools. Because the domain is newly created less than a year ago, it may be part of a broader wave of crypto‑casino frauds; correlating alerts that reference similar page titles or the same registrar can improve early warning. Continued sharing of this indicator set with industry‑wide feeds will help reduce the attack surface.
نطاق تغطية البيانات13 recorded checks
مؤشرات الأمان
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | nezcas.com |
phishing | Phishing Block |
| Hagezi Threat Feed | nezcas.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260105-E5D008 Recipient: abuse@matbao.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.