Why this matters — ICANN RAA §3.18 obligation
On PhishDestroy delivered an evidence-backed abuse report
to support@nicenic.net with the evidence stored for the case at that time.
More than 5 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
bitxroll[.]com
Analyse phishing et sécurité de bitxroll.com
“BITXROLL: Crypto Casino Games & Casino Slot Games - Crypto Gambling”
bitxroll.com — Dernier actif connu (HTTP 307). Type d'arnaque : Crypto Gambling. Résumé des preuves: VT 1/91 (alphaMountain.ai); URLQuery 1 alert; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_PHISH; BL 0; PD 72/100. Bureau d’enregistrement: NiceNIC.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain bitxroll.com was a generic phishing site posing as a crypto gambling platform. It did not impersonate a specific brand but presented itself as 'BITXROLL: Crypto Casino Games & Casino Slot Games - Crypto Gambling,' targeting users with fraudulent gambling schemes. As of the latest verification, bitxroll.com has been taken offline, though it previously exhibited elevated risk indicators typical of phishing operations.
Technical analysis revealed that bitxroll.com was flagged by 2 of 95 VirusTotal security vendors, including Gridinsoft and SOCRadar, and appeared on 1 security blocklist (PhishDestroy). The domain was registered through NiceNIC International Group Co., Limited on February 21, 2026, and resolved to the IP address 188.114.96.3, hosted on Cloudflare’s infrastructure (AS13335). Its SSL certificate was issued by Google Trust Services (WE1), and the site employed technologies such as Node.js, React, Next.js, and Facebook Pixel. The Gridinsoft trust score for the domain was 0/100, further confirming its malicious nature.
Users who interacted with bitxroll.com should monitor their accounts for unauthorized transactions, particularly if cryptocurrency was involved. While no drainer kit was identified, victims should revoke any token approvals granted to unknown contracts and consider transferring funds to a new wallet. For credential-based interactions, passwords should be changed immediately, and two-factor authentication enabled. Reports can be submitted to platforms like Google Safe Browsing, PhishTank, or local cybersecurity authorities to aid in takedown efforts.
Renseignements sur la sécurité réseau Registrar Integrity Alert
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | bitxroll.com |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
L’ICANN a encaissé. La reddition de comptes n’a pas suivi.
Pour ce gTLD, le bureau d’enregistrement ci-dessus opère dans le cadre d’un contrat avec l’ICANN. L’ICANN perçoit des frais annuels, variables et liés aux transactions, associés aux enregistrements, aux renouvellements et aux transferts.
Accréditation : monétisée. Reddition de comptes : veuillez repasser plus tard.
Puis la magie commence : l’ICANN rédige le RAA §3.18, le bureau d’enregistrement enquête sur les abus au sein de sa propre clientèle, et les victimes fournissent gratuitement les preuves pendant que chaque niveau attend qu’un autre agisse. Si cela rassure les victimes, excellent — la facture a fonctionné.
Latest Classified Outcome 2026-08-07 02:40:20 UTC
Casino / Gambling License Verification
Technologies · 9 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
JavaScript library for building user interfaces with component-based architecture.
React framework for production with hybrid static and server rendering.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comModule bundler for modern JavaScript applications.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of bitxroll.com · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
À propos de ce rapport : bitxroll.com
Ce rapport présente les dernières preuves stockées disponibles pour PhishDestroy. Les horodatages sources sont affichés lorsqu'ils sont disponibles ; la disponibilité et les verdicts des fournisseurs peuvent changer après la collecte.
Le site capturé affichait le titre de la page “BITXROLL: Crypto Casino Games & Casino Slot Games - Crypto Gambling”.
Depuis 07/08/2026, bitxroll.com avait des détections provenant des moteurs de sécurité 1.
Si vous pensez que cette liste est inexacte, déposer un recours. Pour en savoir plus sur notre méthodologie, visitez le Page FAQ.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif