# PhishDestroy threat dossier — rainbet-espana.com ================================================================ Fetched: 2026-07-22 13:09:16 UTC Canonical: https://phishdestroy.io/domain/rainbet-espana.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: ChainPatrol, alphaMountain.ai, Forcepoint ThreatSeeker, LevelBlue AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.9.24 Registrar: Dynadot Inc Nameservers: nile.ns.cloudflare.com, roxy.ns.cloudflare.com Registered: 2026-02-27 Expires: 2027-02-27 Page title: Rainbet Casino - Tu Destino de Juegos en Línea en España ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-09-24 Status: INVALID chain Fingerprint: 760eafab722115f908a7f31e305b8c61d1baf021a5eedbda44003c0ec7849d6b ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-22 12:25:17 UTC (by PhishDestroy tracker) First reported: 2026-07-22 10:35:38 UTC (abuse notice filed) Last verified: 2026-07-22 15:02:04 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f895a-5974-7509-8720-9ac5a8d60b2e/ URLQuery: https://urlquery.net/report/22867c89-7d46-486d-b405-79667a1fa335 Wayback Machine: https://web.archive.org/web/*/rainbet-espana.com crt.sh CT logs: https://crt.sh/?q=%25.rainbet-espana.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=rainbet-espana.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/rainbet-espana.com URLhaus: https://urlhaus.abuse.ch/host/rainbet-espana.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 12:25:26 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] rainbet-espana.com high‑risk phishing campaign Analysis Date: July 22, 2026. The domain rainbet-espana.com is currently active and has been classified as a high‑risk generic phishing operation. The domain was registered on February 27, 2026 through Dynadot Inc and uses Cloudflare nameservers nile.ns.cloudflare.com and roxy.ns.cloudflare.com. DNS resolution points to the IP address 104.21.9.24, which is hosted on Cloudflare's edge network. VirusTotal has recorded four detections out of ninety‑five scanned security vendors, indicating that a minority of scanners have identified malicious behavior. The domain is listed on three public security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its reputation as a phishing source. No public information about SSL certificate details, HTTP response codes, page title, or specific brand impersonation has been disclosed, so the exact content served by the site remains unverified. The lack of visible page metadata limits attribution of the phishing kit or targeted brand. The risk rating assigned as high reflects the combination of recent creation, active status, and confirmed detections. Although only four vendors flagged the domain, the presence on multiple blocklists suggests coordinated abuse. The Cloudflare edge IP 104.21.9.24 is shared with other unrelated sites, which may provide some level of anonymity for the operators. Given the observable infrastructure, defenders should treat any traffic to rainbet-espana.com as malicious. Recommended actions include adding the domain and its resolving IP to network firewalls, DNS filtering solutions, and endpoint security blocklists. Continuous monitoring of the IP address for any changes in hosting or additional malicious activity is advised. Organizations should also ensure internal DNS resolvers do not cache the domain and enforce strict outbound filtering to prevent credential leakage. Sharing observed indicators with threat‑intelligence communities will improve collective detection. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260722-36CA78 Favicon MD5: 00f4c6909835c6cf3f0bc13fc21c0da9 TLS cert SHA-256: 760eafab722115f908a7f31e305b8c61d1baf021a5eedbda44003c0ec7849d6b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/rainbet-espana.com/ JSON API: https://api.destroy.tools/v1/check?domain=rainbet-espana.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,059 domains (57,504 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io