app[.]soakwin[.]com
Phishing and security check for app.soakwin.com
As of August 07, 2026, the domain app.soakwin.com has been identified as active phishing infrastructure with an elevated risk profile. Analysis indicates 13 out of 91 security vendors currently flag this domain as malicious according to VirusTotal intelligence. The domain is also listed on at least one security blocklist and has been blocked by PhishDestroy, strengthening the evidence of its association with phishing activity. The domain resolves to IP address 172.67.221.115.
There is currently no confirmed information regarding the specific content or impersonated service, as neither the website title, scam type, nor a targeted brand have been identified in the available data. As such, defenders should treat this domain as a generic phishing threat. The continued active status, coupled with multiple independent detections, suggests this infrastructure is being employed for malicious purposes. Organizations are strongly advised to monitor network activity for connections to this domain, block it across perimeter security controls, and search security logs for historical access.
Pending further investigation into its specific tactics and targets, defenders should maintain heightened vigilance around any traffic to or from app.soakwin.com and its associated IP address. The exact methods by which users are lured or what data is targeted remain unknown at this point. Continued intelligence gathering is recommended to determine the full scope of the threat posed by this domain.
Network Security Intelligence Registrar Integrity Alert
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: soakwin.com
Accreditation and RAA context
Accreditation and RAA context
ICANN Got Paid. Accountability Did Not Arrive.
For the registrable domain soakwin.com behind this subdomain, the registrar above operates under an ICANN contract. ICANN collects annual, variable and transaction-based fees tied to registrations, renewals and transfers.
Accreditation: monetized. Accountability: please check back later.
Then the magic starts: ICANN writes RAA §3.18, the registrar investigates abuse inside its own customer base, and victims deliver the evidence for free while every layer waits for someone else to act. If that makes victims feel safer, excellent—the invoice worked.
Casino / Gambling License Verification
Technologies · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of app.soakwin.com · checked Aug 7, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
About This Report: app.soakwin.com
Stored evidence snapshot. Source timestamps appear where available.
VirusTotal detections for app.soakwin.com: 13 (Aug 7, 2026).
submit an appeal or review the FAQ page.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive