Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
onwin2449[.]net
“Barclays.Net”
Resumen de las pruebas
This domain, onwin2449.net, was identified as a phishing infrastructure specifically designed to impersonate Barclays, a major financial institution. The site operated with the intent to deceive users into divulging sensitive banking credentials, including login details, personal identification numbers, and financial transaction data. Analysis of the domain reveals it hosted fraudulent pages mimicking Barclays' official online banking portal, likely employing social engineering tactics such as urgent account verification requests or fake security alerts to manipulate victims into submitting their credentials. The domain's page title, 'Sorry, the website has been stopped,' suggests it was recently taken offline, potentially following detection or enforcement action, though residual risk remains for users who may have interacted with it prior to deactivation. Evidence supporting the malicious classification of onwin2449.net includes multiple technical indicators. The domain was flagged by 23 out of 95 security vendors on VirusTotal, indicating broad consensus among threat intelligence sources regarding its fraudulent nature. Registered through Internet Domain Service BS Corp. on September 21, 2025, the domain's recent creation aligns with common phishing lifecycle patterns, where newly registered domains are frequently abused for short-term campaigns. Infrastructure analysis reveals the domain resolved to the IP address 91.92.240.61, hosted under AS202412 (Omegatech LTD) in Germany, a network previously associated with malicious activity. Additionally, the domain appears on at least one security blocklist, and its SSL certificate, issued by Let's Encrypt (R13), was likely used to lend an appearance of legitimacy to the fraudulent site. The combination of these factors—recent registration, high detection rate, and association with known malicious infrastructure—elevates the risk assessment for this domain. Users who visited onwin2449.net or interacted with any content hosted on this domain should take immediate corrective action to mitigate potential compromise. First, any credentials entered on the site must be considered exposed and should be changed immediately across all platforms where the same or similar passwords were used. Affected individuals should contact Barclays directly through verified channels to report potential fraud and monitor their accounts for unauthorized transactions. Enabling multi-factor authentication on all financial and sensitive accounts is strongly recommended to prevent unauthorized access, even if credentials were compromised. Additionally, users should review their systems for signs of malware or unauthorized access, as phishing sites may distribute malicious payloads or redirect to secondary infection vectors. Organizations should update their security controls to block the domain and its associated IP address (91.92.240.61) to prevent further exposure.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260214-3C04CF- Título de la página capturada
- Sorry, the website has been stopped
- Artefacto PDF
- Evidencia en PDF
Texto completo de la evidencia
Acceptable Use Policy (AUP): The domain onwin2449.net is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations, and the ongoing fraudulent activities associated with this domain warrant immediate action.
Applicable Laws (IS):
Act on Electronic Communications and the Protection of Privacy (No. 81/2003): This law prohibits unauthorized access to data and fraudulent use of electronic communications, which is applicable to the phishing activities conducted by this domain.
Criminal Code of Iceland (No. 19/1940), Chapter 27: This chapter addresses fraud and deception, making it illegal to deceive individuals for financial gain, which is precisely what phishing entails.
Regulatory Note: Failure to take immediate action against onwin2449.net may result in regulatory scrutiny and potential liability under applicable laws. Non-compliance could expose your organization to legal repercussions.
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | onwin2449.net |
malicious | Sinkholed |
| OpenDNS | onwin2449.net |
phishing | Phishing Block |
| DigiCert UltraDNS | onwin2449.net |
malicious | Sinkholed |
| Quad9 DNS | onwin2449.net |
malicious | Sinkholed |
| DNS4EU | onwin2449.net |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Inaccesible → Accesible
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.