Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 25 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
rain-bet[.]pro
“Rainbet – Krypto-Casino & Sportwetten in Deutschland spielen”
Evidence Summary
Analysis of the domain rain-bet.pro indicates active credential phishing infrastructure. Registered on December 7, 2025, through Dynadot Inc, the domain remains operational as of July 16, 2026. It resolves to IP address 188.114.97.3 and uses Cloudflare nameservers (kipp.ns.cloudflare.com, lola.ns.cloudflare.com). Three of 91 security vendors on VirusTotal have flagged the domain, suggesting detection of malicious activity, though the exact nature of the phishing content is not yet confirmed. The domain's creation date aligns with typical phishing campaign timelines, and its continued activity increases the likelihood of ongoing credential harvesting. Defenders should treat this domain as high-risk and prioritize blocking or monitoring access to 188.114.97.3 and associated subdomains. No specific brand impersonation or phishing kit details are available at this time, but the domain's structure and infrastructure are consistent with credential theft operations. Further investigation into connected IPs, SSL certificates, and hosting patterns is recommended to identify related threats.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260717-13F37B- Captured page title
- Rainbet – Krypto-Casino & Sportwetten in Deutschland spielen
Full evidence text
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | rain-bet.pro |
malicious | Sinkholed |
| Quad9 DNS | rain-bet.pro |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
8 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Technologies
2 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive