# PhishDestroy threat dossier — rainbetcasino.bet ================================================================ Fetched: 2026-07-29 09:26:40 UTC Canonical: https://phishdestroy.io/domain/rainbetcasino.bet/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: ChainPatrol, alphaMountain.ai, Fortinet, Gridinsoft, LevelBlue Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.20.246 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Dynadot Inc Nameservers: armfazh.ns.cloudflare.com, ryleigh.ns.cloudflare.com Registered: 2026-02-05 Expires: 2027-02-05 Page title: Rainbet | Bono De Bienvenida De Hasta €1,300 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-01 Status: INVALID chain Fingerprint: cef8f96785a8a56aea0adf7db2d4ac9c07d6aa6c7bb8b2360dfbb532ce83dc3d ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-05 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 18:28:20 UTC (by PhishDestroy tracker) First reported: 2026-07-28 16:35:50 UTC (abuse notice filed) Last verified: 2026-07-29 09:34:09 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa9ae-213c-7748-9204-f9d45dea3519/ URLQuery: https://urlquery.net/report/e12fa1f5-14e7-496b-a469-bf67c73efcef Wayback Machine: https://web.archive.org/web/*/rainbetcasino.bet crt.sh CT logs: https://crt.sh/?q=%25.rainbetcasino.bet Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=rainbetcasino.bet AlienVault OTX: https://otx.alienvault.com/indicator/domain/rainbetcasino.bet URLhaus: https://urlhaus.abuse.ch/host/rainbetcasino.bet/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 18:30:31 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] rainbetcasino.bet Generic Phishing Alert The domain rainbetcasino.bet was registered on February 5, 2026 through Dynadot Inc and is currently hosted on Cloudflare infrastructure, resolving to IP address 104.21.20.246. Authority records list armfazh.ns.cloudflare.com and ryleigh.ns.cloudflare.com as its nameservers, confirming the use of Cloudflare’s DNS service. VirusTotal scans have returned detections from five of ninety‑one security vendors, indicating that the domain exhibits characteristics commonly associated with malicious activity. Independent threat‑intel feeds have already blocked the domain via PhishDestroy, MetaMask, and SEAL, and it appears on three additional security blocklists, reinforcing the assessment of high risk. The domain’s status is marked as active, and no public evidence of a valid SSL certificate, page title, or explicit impersonated brand has been disclosed. Consequently, defenders lack visibility into the exact payload or credential‑harvesting tactics employed, but the existing indicators demonstrate that the infrastructure is being leveraged for generic phishing campaigns. Mitigation recommendations include adding rainbetcasino.bet and its resolving IP 104.21.20.246 to network deny lists, monitoring for outbound connections to the Cloudflare edge nodes, and correlating any authentication attempts against internal accounts with the timing of this domain’s activity. Continuous re‑evaluation of VirusTotal and additional sandbox analyses should be performed to capture any evolving payloads, while threat‑hunting teams should watch for related domains that share the same nameserver pattern or registrar footprint. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-687864 Favicon MD5: 3f2cf897d3a2e155543a3a49a66829e9 TLS cert SHA-256: cef8f96785a8a56aea0adf7db2d4ac9c07d6aa6c7bb8b2360dfbb532ce83dc3d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/rainbetcasino.bet/ JSON API: https://api.destroy.tools/v1/check?domain=rainbetcasino.bet Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 194,327 domains (83,211 alive under monitoring, 108,481 confirmed takedowns/dead). Site: https://phishdestroy.io