gawux[.]com
Análisis de phishing y seguridad de gawux.com
“Gawux: Most Popular Online Crypto Casino Based on Blockchain”
gawux.com — Contenido no disponible (HTTP 502). Suplantación de marca: Genericcrypto; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 11/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. Registrador: Realtime.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, gawux.com, was registered on 21 February 2026 through Realtime Register B.V. and is hosted behind Cloudflare's network (AS13335) with the A record 188.114.97.3 located in the United States. The authoritative nameservers are bayan.ns.cloudflare.com and colette.ns.cloudflare.com. The site is presently taken offline, but it was previously classified as a crypto‑scam phishing page, presenting itself as “Gawux: Most Popular Online Crypto Casino Based on Blockchain”. No SSL certificate was observed, indicating that the site operated without HTTPS encryption.
Reputation scoring is extremely low, with a Gridinsoft trust score of 1 out of 100, and the domain appears on a single security blocklist. PhishDestroy has already listed the site as blocked. VirusTotal analysis shows that 11 of 95 scanned security vendors flagged the domain, providing independent confirmation of malicious intent. The phishing kit in use has been identified as the “Gambler Scam” kit, which is frequently associated with fraudulent online gambling and cryptocurrency‑related lures.
The limited public visibility, combined with the low trust score and multiple vendor detections, suggests a high probability that the domain was used to harvest credentials or funds from unsuspecting victims. Defenders should add gawux.com to network and endpoint blocklists, enforce DNS filtering for the associated IP address 188.114.97.3, and monitor for any new domains registered by the same registrar that resolve to Cloudflare IP ranges. Because the site currently returns no SSL certificate and is offline, further passive DNS and historical certificate monitoring may reveal additional infrastructure reuse. Continuous vigilance for the Gambler Scam kit payloads is recommended, as attackers often repurpose the same code across newly registered domains.
Señales de seguridad
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
PD-20260218-30DF1C Recipient: rtr-security-threats@realtimeregister.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.