# PhishDestroy threat dossier — rainbetcasinosau.com ================================================================ Fetched: 2026-07-29 15:02:33 UTC Canonical: https://phishdestroy.io/domain/rainbetcasinosau.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: ChainPatrol, alphaMountain.ai, Gridinsoft Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.9.146 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: NAMECHEAP INC Nameservers: dara.ns.cloudflare.com, lou.ns.cloudflare.com Registered: 2026-03-30 Expires: 2027-03-30 Page title: Rainbet Casino: Crypto Slots, Provably Fair Games & Fast Withdrawals ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: YE2 Status: INVALID chain ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-30 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 18:24:11 UTC (by PhishDestroy tracker) First reported: 2026-07-28 16:30:11 UTC (abuse notice filed) Last verified: 2026-07-29 16:20:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa9ae-1edb-7008-9645-e266d05f162f/ URLQuery: https://urlquery.net/report/712efa78-cfe0-4e33-9137-a832984d4c03 Wayback Machine: https://web.archive.org/web/*/rainbetcasinosau.com crt.sh CT logs: https://crt.sh/?q=%25.rainbetcasinosau.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=rainbetcasinosau.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/rainbetcasinosau.com URLhaus: https://urlhaus.abuse.ch/host/rainbetcasinosau.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 18:31:18 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] rainbetcasinosau.com — Online Casino Phishing Domain Analysis of rainbetcasinosau.com indicates a high-risk phishing domain targeting online casino users, registered on March 30, 2026, through NAMECHEAP INC. The domain currently resolves to IP address 104.21.9.146 and utilizes Cloudflare nameservers (dara.ns.cloudflare.com and lou.ns.cloudflare.com), a common infrastructure choice for threat actors seeking to obscure hosting origins and evade detection. As of July 28, 2026, the domain remains active and is flagged by three security blocklists, including PhishDestroy, MetaMask, and SEAL, suggesting confirmed malicious activity or ongoing abuse. VirusTotal reports that 3 out of 91 security vendors detect this domain as malicious, though the specific detection context (e.g., phishing, malware distribution) is not detailed in available intelligence. The domain's recent creation date, combined with its presence on multiple blocklists, aligns with patterns observed in short-lived phishing campaigns designed to exploit users before takedown. Infrastructure analysis reveals reliance on Cloudflare, which may complicate efforts to identify the true hosting provider or geographic origin of the malicious content. No additional details regarding the domain's SSL certificate, HTTP response status, or page content (e.g., brand impersonation, phishing kit) are available in the current evidence. Defenders should treat this domain as actively malicious and prioritize blocking it at the DNS or network level. Organizations using MetaMask or SEAL protections may already have mitigations in place, but verification of endpoint and gateway-level blocks is recommended. Given the domain's registration through a widely abused registrar and its persistence despite blocklist inclusion, monitoring for related domains or IP shifts is advised. Further investigation into the domain's hosting infrastructure, SSL fingerprint, and any associated malware samples could provide additional context for incident response teams. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-40936E ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/rainbetcasinosau.com/ JSON API: https://api.destroy.tools/v1/check?domain=rainbetcasinosau.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,484 domains (83,251 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io