MALICIOUS — CRITICAL
coraslots[.]net
Analysis of coraslots.net, created on 21 February 2026 and currently taken offline, shows multiple indicators of malicious activity targeting cryptocurrency users.
- VirusTotal
- 16/93
- Blocklists
- No stored match
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
coraslots.net — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Genericcrypto; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, ESET); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 100/100. Registrar: NiceNIC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of coraslots.net, created on 21 February 2026 and currently taken offline, shows multiple indicators of malicious activity targeting cryptocurrency users. The domain resolves to IP address 188.114.96.3, which is owned by Cloudflare, Inc. (AS13335) and located in the United States. Both authoritative name servers are Cloudflare hosts (gina.ns.cloudflare.com and tate.ns.cloudflare.com), confirming the use of a reputable CDN for anonymity and rapid deployment. No TLS certificate is presented, indicating the site operated without HTTPS encryption, a common trait of low‑effort phishing deployments.
The page title advertised "Coraslots: Most Popular Online Crypto Casino Based on Blockchain," and the observed scam type is classified as a crypto scam, consistent with the "Gambler Scam" phishing kit identified in related intelligence. Reputation services rate the domain poorly, with Scamadviser assigning an 11 out of 100 trust score. VirusTotal scans flagged the domain on 16 of 93 security engines, and the site is listed on at least one public blocklist, having been actively blocked by PhishDestroy. Registration was performed through NiceNIC International Group Co., Limited, a registrar known to host transient malicious domains.
While the site is presently offline, the infrastructure details—Cloudflare front‑end, lack of SSL, and the specific gambling‑oriented phishing kit—suggest a focused campaign aimed at extracting cryptocurrency credentials or payments from unsuspecting victims. Defenders should continue to monitor the IP address for re‑use, enforce blocklist updates that include coraslots.net, and consider broader heuristic rules that flag similar gambling‑related crypto language in URLs or page titles. Additional verification, such as checking for any residual DNS records or associated subdomains, would help confirm whether the threat actor has pivoted to new infrastructure.
Datenabdeckung13 recorded checks
Sicherheitssignale
Erkenntnisse zur Netzwerksicherheit Registrar context
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 03:48:39 UTC
Verlauf der Missbrauchsmeldungen · 2 stored reports over 25 days · click to expand
-
Report #1 Escalation 45h still active Feb 8, 2026 · 18:21 UTCESCALATION #2 (45h active): Phishing - coraslots[.]netsupport@nicenic.net
-
Report #2 ICANN CC 629h still active Mar 5, 2026 · 01:37 UTCESCALATION #3 (629h active): Phishing - coraslots[.]netabuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
Casino / Gambling License Verification
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe BerichteIndependent lookups and source reports
PD-20260206-1767E1 Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.