Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 20 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
rainbett[.]fr
“Casino Rainbet en ligne France – Inscription rapide, gros bonus”
Resumen de las pruebas
The domain rainbett.fr was registered through NETIM on March 17, 2026. Its authoritative name servers huxley.ns.cloudflare.com and tessa.ns.cloudflare.com resolve the domain to IP address 188.114.97.3, which belongs to Cloudflare, Inc. and is geolocated in Canada. The site presents a TLS certificate issued by Let’s Encrypt, indicating encrypted HTTPS access. Automated analysis reveals the presence of PHP runtime, IPinfo API usage, HSTS headers, Cloudflare Browser Insights, and support for HTTP/3, all consistent with a Cloudflare‑protected web service.
Threat intelligence shows the domain appears on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal reports that three of ninety‑one scanning engines have flagged the domain, reinforcing the suspicion of malicious activity. The classification assigned is generic phishing, and the risk level is high. The domain remains active as of the report date, July 22, 2026.
While the current data confirms the infrastructure and detection posture, no public page title or content analysis has been published, leaving the exact phishing lure undefined. Consequently, defenders should continue to enforce blocklist rules, monitor DNS resolutions for 188.114.97.3, and consider quarantine or removal of any traffic to rainbett.fr. Additional sandbox or manual inspection of the web payload is recommended to identify the targeted brand or credential‑stealing mechanism, should the site become reachable.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260722-20C324
Texto completo de la evidencia
Policy Violations: “Strict abuse policy classifying phishing, malware, fraud and botnet activity as illegal domain use; registrar may suspend or terminate affected domains.”
Applicable Laws: French Penal Code Art.323-1+; EU Directive 2013/40/EU
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | rainbett.fr |
malicious | Sinkholed |
| Quad9 DNS | rainbett.fr |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
8 fuentes externas supervisadas Sin coincidencias
Casino / Gambling License Verification
Tecnologías
6 tecnologías identificadas con alta confianza
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of rainbett.fr · checked Jul 22, 2026
Análisis de la configuración del sitio
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.