Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 21 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mgmslots[.]co
“Mgmslots · Spin & Win Big”
Evidence Summary
Analysis of the domain mgmslots.co indicates a high-risk phishing campaign targeting online gambling users. Registered on July 11, 2026, through Tucows Domains Inc., the domain remains active as of July 22, 2026, resolving to the IP address 104.21.18.39. Infrastructure analysis reveals Cloudflare nameservers (garret.ns.cloudflare.com and oaklyn.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. Detection metrics show the domain is flagged by 6 of 95 security vendors on VirusTotal, a modest but notable signal given the domain's recent registration.
Additionally, it appears on one security blocklist, further supporting its classification as malicious. The domain's purpose aligns with generic phishing activity, though the exact content or targeted brand has not been confirmed through available evidence. No specific phishing kit, page title, or brand impersonation details were provided, limiting further attribution. Defenders should note the short lifespan of the domain—11 days at the time of this report—which is consistent with phishing campaigns designed to operate briefly before detection or takedown.
The use of Cloudflare nameservers may complicate IP-based blocking, though the resolved IP (104.21.18.39) can be monitored for additional malicious domains. Organizations are advised to block the domain at the DNS or proxy level and monitor associated infrastructure for related threats. Given the domain's recent registration and active status, continued vigilance is recommended, particularly for sectors frequently targeted by credential-harvesting campaigns, such as online gaming and financial services. No evidence currently suggests widespread adoption by threat actors, but the domain's detection profile warrants inclusion in threat intelligence feeds.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260722-849DFD
Full evidence text
Policy Violations: Participates in DNS Abuse Framework; explicitly recognizes phishing, malware, botnets, pharming, spam-as-vector as abuse requiring registrar action
Applicable Laws: Criminal Code §342.1 (unauthorized access), §380 (fraud)
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | mgmslots.co |
malicious | Sinkholed |
| DNS4EU | mgmslots.co |
malicious | Sinkholed |
| OpenDNS | mgmslots.co |
phishing | Phishing Block |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Casino / Gambling License Verification
Technologies
4 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of mgmslots.co · checked Jul 22, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive