This investigation documents the infrastructure and detection profile of rainbet-win.com, a domain created on July 24 2026 and currently classified as a high‑risk generic phishing site. The domain is hosted on the IPv4 address 183.81.169.24 and is serviced by four nameservers—ns1.pananames.com, ns2.pananames.com, ns3.pananames.com, and ns4.pananames.com—registered through URL SOLUTIONS INC. Within three security blocklists, the domain is listed and has been actively blocked by the PhishDestroy, MetaMask, and SEAL filtering platforms.
VirusTotal analysis shows that 2 of 91 scanned security vendors have flagged the domain, indicating partial detection coverage. As of the report date, July 28 2026, the domain remains active and continues to resolve to the same IP address, suggesting that the malicious infrastructure is still operational. No additional public intelligence such as page titles, SSL certificates, or brand‑specific lures has been disclosed, leaving the content of the hosted page unverified.
Defenders should add rainbet-win.com to local deny lists, enforce DNS‑level blocking, and monitor outbound connections to 183.81.169.24. Continuous re‑evaluation of the domain’s status on blocklists and periodic rescans with broader vendor sets are recommended to capture any escalation in malicious activity.