Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
onwin2434[.]net
“Barclays.Net”
Resumen de las pruebas
This domain, onwin2434.net, is flagged as a brand impersonation threat specifically targeting Barclays, a major financial institution. The site is designed to mimic legitimate banking portals, tricking users into entering sensitive credentials such as login details, personal identification numbers, or financial information. Such impersonation tactics are commonly used to facilitate unauthorized account access, financial fraud, or identity theft. Given the elevated risk level, users who interact with this domain may expose themselves to immediate financial or data compromise. Analysis indicates that onwin2434.net was registered on February 21, 2026, through Internet Domain Service BS Corp, a registrar frequently associated with high-risk domains. The domain resolves to the IP address 91.92.240.61, hosted under AS202412 (Omegatech LTD) in Germany, an autonomous system with a history of hosting malicious infrastructure. Security vendors on VirusTotal have flagged this domain as malicious, with 21 out of 95 engines detecting it as a threat. Additionally, the domain appears on one security blocklist and uses a Let's Encrypt SSL certificate (R13), which, while providing encryption, does not validate the legitimacy of the site. The page title, 'Sorry, the website has been stopped,' suggests recent takedown efforts, though residual risk remains for users who may have engaged with the site prior to its deactivation. Users who visited onwin2434.net should take immediate action to mitigate potential risks. First, disconnect any devices used to access the site from the internet to prevent further data exfiltration. Run a full antivirus scan to detect and remove any malware or spyware that may have been installed. If any credentials were entered, change passwords immediately for the affected accounts and enable multi-factor authentication where available. Monitor financial statements and credit reports for unauthorized transactions or signs of identity theft. Report the incident to the targeted brand’s fraud department and consider filing a report with relevant cybersecurity authorities or consumer protection agencies. Given the domain’s association with brand impersonation, users should remain vigilant for follow-up phishing attempts via email or SMS, as attackers may attempt to exploit previously collected contact information.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260214-FB84DB- Título de la página capturada
- Sorry, the website has been stopped
- Artefacto PDF
- Evidencia en PDF
Texto completo de la evidencia
Acceptable Use Policy (AUP): The domain onwin2434.net is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any activities that are illegal or harmful to others.
Applicable Laws (IS):
Criminal Code of Iceland (No. 19/1940), Section 233: This section addresses fraud and deception, making it illegal to deceive individuals for financial gain.
Act on Electronic Communications (No. 81/2003), Section 7: This law prohibits the use of electronic communications for the purpose of phishing or other fraudulent activities.
Regulatory Note: Failure to take immediate action against this domain may result in regulatory scrutiny and potential liability under Icelandic law. Non-compliance with your own policies and applicable laws could expose your organization to legal repercussions.
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | onwin2434.net |
malicious | Sinkholed |
| OpenDNS | onwin2434.net |
phishing | Phishing Block |
| DigiCert UltraDNS | onwin2434.net |
malicious | Sinkholed |
| DNS4EU | onwin2434.net |
malicious | Sinkholed |
| Quad9 DNS | onwin2434.net |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Inaccesible → Accesible
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.