Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kesowin[.]com
“Kesowin: Most Popular Online Crypto Casino Based on Blockchain”
Evidence Summary
kesowin.com is an active domain first observed on May 16 2026. The site resolves to 104.21.35.254 and is fronted by Cloudflare, using the nameservers alina.ns.cloudflare.com and chris.ns.cloudflare.com. TLS is provided by a Let’s Encrypt certificate (E8). The page title advertises “Kesowin: Most Popular Online Crypto Casino Based on Blockchain,” indicating a crypto‑casino lure. Infrastructure analysis shows the domain is hosted in Canada and is associated with the “Gambler Scam” phishing kit, classified as brand impersonation. Reputation services assign a Gridinsoft score of 1 / 100 and a Scamadviser score of 16 / 100, reflecting extremely low trust. VirusTotal reports 19 of 91 scanners flagging the host, and the domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL. Detected tracking technologies include Twitter Ads, Facebook Pixel, and Cloudflare protection, suggesting the operators are leveraging commercial ad networks for traffic acquisition. Current evidence confirms the site is actively delivering a phishing lure targeting users interested in cryptocurrency gambling; however, the exact content displayed to victims has not been captured. Defenders should block the domain at DNS and proxy layers, monitor outbound connections to the associated IP, and add the host to internal threat intel feeds. Continuous observation is recommended to detect any changes in payload or target branding.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260518-0FB20E- Captured page title
- Kesowin: Most Popular Online Crypto Casino Based on Blockchain
- PDF artifact
- PDF evidence
Legal basis
Full evidence text
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Report history 1
- Report 2 ⚠️ ESCALATION #2 (126h active): Phishing - kesowin[.]com
Data Coverage
Security Signals
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | kesowin.com |
phishing | Phishing Block |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
8 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
-
Domain status
Unreachable → Reachable
Community reports
Reported by 1 community member, first seen May 18, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Community intelligence
1 community report
CategoryOTHER_INVESTMENT_SCAM
They are asking to pay money to unlock withdrawals. Legitimate platforms usually verify identity with documents, not by forcing an additional deposit. can't provide: a verifiable license number, a regulator link, clear compliance documentation, and support staff who can explain v
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of kesowin.com · checked May 18, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive