Zum Sicherheitsbericht springen
Checked 09.08.2026 Ref 4FF2EC70

MALICIOUS — HIGH

Phishing- und Sicherheitsprüfung für gusewin.com

gusewin[.]com

This domain is flagged as an elevated-risk brand impersonation scheme targeting cryptocurrency gambling platforms.

67/100 evidence score · High
VirusTotal
4/91
Blocklists
No stored match
Verfügbarkeit
Erreichbar · Zugang eingeschränkt · HTTP 403
Report / Add Evidence Appeal this listing
2026-05-10 22:11 UTCErreichbar · Zugang eingeschränkt · HTTP 403

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Diese Domain wurde als bösartig markiert.
Sicherheits-Engines melden eine Entdeckung: 4. Seien Sie äußerst vorsichtig – Geben Sie keine Anmeldeinformationen oder persönlichen Daten ein.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . It contains 2 outgoing records; the latest is dated . The recorded recipient is abuse@trustname.com. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
3 months
Reports sent
2
Latest case ID
PD-1778458291-gusewin.com
Current status
HTTP 403 at latest stored check
Jump to section
Berichtsübersicht

gusewin.com — Erreichbar · Zugang eingeschränkt (HTTP 403). Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker); URLQuery 6 alerts; PhishDestroy score 67/100. Registrar: Fewmoretaps OU d/b/a T….

Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.

Evidence Analysis

Ref 4FF2EC70

This domain is flagged as an elevated-risk brand impersonation scheme targeting cryptocurrency gambling platforms. Analysis indicates gusewin.com mimics legitimate crypto casino services, presenting itself as 'Pazewin: Most Popular Online Crypto Casino Based on Blockchain' to deceive users into depositing digital assets. The specific threat type involves fraudulent representation of a gambling brand to facilitate unauthorized transactions or data harvesting, with potential secondary risks including crypto wallet drainers or credential theft. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain was registered on April 28, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar frequently associated with high-risk domains. It resolves to IP address 104.21.76.105 and is currently offline, though prior scans show it was active on two security blocklists, including PhishDestroy and OISD. VirusTotal reports 17 out of 95 security vendors flagging the domain as malicious, while Gridinsoft assigns a trust score of 1 out of 100. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and fraudulent sites. AlienVault OTX records the domain in one threat intelligence pulse, further corroborating its malicious classification. Mitigation for this brand impersonation threat requires multi-layered defenses. Network administrators should implement DNS-level blocking for gusewin.com and its associated IP 104.21.76.105, while monitoring for related domains registered through the same registrar. Endpoint protection systems should be configured to detect and prevent access to domains with similar naming patterns (e.g., *-win.com) or those impersonating gambling platforms. Users should be educated to verify domain authenticity through official brand channels and avoid interacting with unsolicited gambling offers, particularly those promoting crypto deposits. Organizations processing cryptocurrency transactions should implement additional verification steps for domains created within the last 12 months, given the prevalence of newly registered domains in fraud campaigns.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
6 threat alerts
OTX references
URLScan
URLScan
Gridinsoft
1/100
TLS-Zertifikat
Let's Encrypt
Alter
3 mo
Beobachteter Status
Erreichbar · Zugang eingeschränkt 403
PhishDestroy
DestroyList
Gelistet
Reports Sent
2
Datenabdeckung13 recorded checks
VirusTotal 4 / 91 URLQuery 6 threat-system alerts PhishStats nicht geprüft OTX 1 community reference CF-Radar scan completed URLScan capture gespeicherter Bericht URLScan verdict Analyse abgeschlossen DNS-Sperren nicht geprüft TLS valid certificate, 61d WHOIS 3 mo old Screenshot 2 captures · 2 sources Weiterleitungskette nicht untersucht Gridinsoft 1/100
Sicherheitssignale
GS Gridinsoft Analysis 1 / 100
5 0 2 3 29
Erkenntnisse zur Netzwerksicherheit Registrar context
Threat Detection Systems 6 alerts
Detection System Indicator Verdict Alert
OpenDNS pazewin.com phishing Phishing Block
DNS4EU pazewin.com malicious Sinkholed
Hagezi Threat Feed pazewin.com malicious Sinkholed
OpenDNS gusewin.com phishing Phishing Block
Hagezi Threat Feed gusewin.com malicious Sinkholed
DNS4EU gusewin.com malicious Sinkholed
Registrar context Trustname
Stored registration data identifies Trustname / Fewmoretaps OÜ (IANA 4318) as the registrar. PhishDestroy maintains a separate registrar investigation; that material is contextual and is not an independent detection for this domain.
Trustname Investigation

Pipeline zur Reaktion auf Sicherheitsbedrohungen

Entdeckung
Checks
Reports
Verfügbarkeit
15/16
Bedrohung erkannt
gusewin.com erkannt und für eine vollständige Analyse in die Warteschlange gestellt
11.05.2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
URLScan-Analyse abgeschlossen; Dieses Web-Capture-Ergebnis ändert nichts an der Beurteilung der Seitenbedrohung · score 0
29.07.2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
4/91 recorded on VirusTotal
18.07.2026
Google Safe Browsing
29.04.2026
OTX Community References
1 community publication reference on AlienVault OTX. References are not vendor verdicts and are excluded from the evidence score.
29.04.2026
Registrar Context: Trustname
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
Der Bericht enthält gespeicherte Technologie- oder forensische Analyseergebnisse.
09.08.2026
VT detections increased by 13
+13 new detections (4 → 17): ADMINUSLabs, BitDefender, CRDF, ESET +9
26.06.2026
Initial Abuse Report (#1)
Sent to 3 abuse contacts at Fewmoretaps OU d/b/a Trustname.com with forensic evidence
abuse@trustname.comabuse@verisign-grs.comcompliance@icann.org
11.05.2026
ICANN Escalation #2
Escalation #2 sent to 3 recipients including ICANN Compliance — follow-up record after a previous report
abuse@trustname.comabuse@verisign-grs.comcompliance@icann.org
13.05.2026
2 Reports Filed
2 report records were stored over 90 days; current observed status: Erreichbar · Zugang eingeschränkt
DestroyList veröffentlicht
11.05.2026
Monitoring Continues
Die Domäne bleibt erreichbar oder zugriffsbeschränkt; Zukünftige Überprüfungen könnten diese Beobachtung aktualisieren.

Status der öffentlichen Sperrliste

Gespeicherte Aufnahme

Seitentitel
Pazewin: Most Popular Online Crypto Casino Based on Blockchain
TLS-Zertifikat
Valid transport encryption · Ausgestellt von Let's Encrypt · valid for 61 days

Domain-Intelligenz

Domain
URLScan Verdict Analyse abgeschlossen score 0 report ↗
Server / ASN cast-sec · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Die Edge-IP-Reputation wird dieser Domäne nicht zugeordnet.
Registrar Fewmoretaps OU d/b/a T… BY(BY) PhishDestroy Investigation
IP-Adresse 104.21.76.105 CDN
StandortCA Toronto, CA
NetzwerkAS13335 · Cloudflare, Inc.
Die Ursprungs-IP ist hinter einem CDN-Proxy verborgen. Reverse-IP-Ergebnisse für die Edge-Adresse enthalten nicht verwandte Mandanten; Um den Ursprung zu finden, sind passive DNS- oder Zertifikatstransparenzdaten erforderlich.
RegistrierungErstellt 28.04.2026 (102d)
HTTP-Status403 Forbidden
Elapsed Since First Report 69 days
Was wir zählen Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Erreichbar · Zugang eingeschränkt.
Minimum notice count 2 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Was jeder Bericht enthält Gespeicherte Ausgangsberichtsaufzeichnungen können auf zu diesem Zeitpunkt verfügbare Beweise verweisen, wie z. B. Urteile von Anbietern, Registrierungsdaten, Hosting-Details, Klassifizierungen oder Screenshots. Diese Seite lässt keine Rückschlüsse auf die genaue zugestellte Nutzlast, den Empfang, die Bestätigung oder die Aktion eines Empfängers zu.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Technische DetailsDNS, SSL-SANs, Zeitstempel
Erstmals entdeckt11.05.2026
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Nameserverleonard.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 30.03.2026scanned 28.04.2026
Case ID
ICANN OVERSIGHT

Akkreditierung und RAA-Kontext

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nichts wird automatisch gesendet.
Verlauf der Missbrauchsmeldungen · 2 stored reports over 2 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
2 abuse reports filed over 90 days — latest observed status: Erreichbar · Zugang eingeschränkt
The records name Fewmoretaps OU d/b/a Trustname.com as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
2
reports
90
days
ICANN CC
  1. Report #1 ICANN CC May 11, 2026 · 03:11 UTC
    ESCALATION #1 (0h active): Phishing - gusewin[.]com
    abuse@trustname.com abuse@verisign-grs.com compliance@icann.org
  2. Report #2 ICANN CC 45h still active May 13, 2026 · 00:58 UTC
    ESCALATION #2 (45h active): Phishing - gusewin[.]com
    abuse@trustname.com abuse@verisign-grs.com compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling
Technologien · 1 identified
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100 % Konfidenz
Detected via Cloudflare Radar · Wappalyzer engine
Diese Domain melden Reichen Sie Beweismaterial ein und helfen Sie mit, andere zu schützen

VirusTotal-Analyse

4 / 91 Sicherheitsanbieter haben diese Domain markiert
View on VT
Last analyzed
alphaMountain.ai
Chong Lua Dao
CyRadar
Forcepoint ThreatSeeker
Website-Performanceanalyse

Google PageSpeed Insights — mobile performance audit of gusewin.com · checked Jun 26, 2026

100
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
1.82s
Largest Contentful Paint
CLS
0.019
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.76s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.

Europol
Finden Sie den offiziellen Meldekanal für Ihr EU-Land
National police directory
Vorsicht vor Betrügern, die mit der Rückforderung von Geldern locken! Kriminelle nehmen unter Umständen erneut Kontakt zu Opfern auf und geben dabei vor, Ermittler, Anwälte oder Beitreibungsbeamte zu sein. Zahlen Sie keine Vorabgebühren und geben Sie keine Anmeldeinformationen weiter. Erfahren Sie mehr über Betrug im Zusammenhang mit Wiederaufbaumaßnahmen →

Melden Sie sich bei Ihren örtlichen Behörden

Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.

97-Länder-Verzeichnis
KI-gestützter Entwurf – Vorfalldetails werden vom KI-Anbieter verarbeitet Überprüfen Sie es und reichen Sie es selbst ein
Diesen Bericht einbettenRead-only HTML widget
HTML · IFRAME

Diesen Bericht einbetten

Teilen Sie diese Bedrohungsinformationen auf Ihrer Website oder in Ihrem Blog

embed.html
<iframe
  src="https://phishdestroy.io/de/embed/domain/gusewin.com"
  title="PhishDestroy threat report for gusewin.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Ein sehr aufrichtiges Dankesschreiben

Generator für satirische Entwürfe

Empfänger
Gebührenkontext

Satirischer Entwurf. Die Gebührenangaben sind Schätzungen; eine genaue Zuordnung zu dieser Domain wird nicht behauptet.