toavex[.]com
“Toavex: Most Popular Online Crypto Casino Based on Blockchain”
साक्ष्य सारांश
On 23 July 2026, investigators examined the domain toavex.com, which was observed hosting a page titled “Toavex: Most Popular Online Crypto Casino Based on Blockchain.” The site was classified as a crypto‑scam phishing operation and associated with the publicly‑available “Gambler Scam” phishing kit. Registration information indicates the domain was created on 21 February 2026 through NiceNIC International Group Co., Limited, and the authoritative name servers are skip.ns.cloudflare.com and violet.ns.cloudflare.com, pointing to Cloudflare’s DNS service. DNS resolution returns the address 188.114.96.3, an IP owned by AS13335 (Cloudflare, Inc.) located in the United States. No TLS certificate was presented for the domain, suggesting the site was served over plain HTTP at the time of analysis.
Threat intelligence feeds have added the domain to a single security blocklist, and it was blocked by the PhishDestroy service. VirusTotal scans reported 13 detections out of 93 security vendors, reinforcing the malicious assessment. The hosting provider, Cloudflare, provides DDoS mitigation and CDN services, which may obscure the true origin of the malicious operator. The current operational status is “taken offline,” meaning the site is no longer reachable, but the infrastructure artifacts remain valuable for attribution and for detecting future re‑use of the same assets.
Uncertainty remains regarding the specific actors behind the campaign, the exact phishing payload delivered, and whether the domain may be re‑registered for a new campaign. Defenders should continue to monitor the IP address 188.114.96.3 and the associated Cloudflare name servers for any resurgence, enforce blocklist entries for toavex.com across web gateways, and consider adding the domain to internal URL filtering policies. Additional hunting can leverage the “Gambler Scam” kit signatures and the observed page title to locate replicas or variants that may target the same cryptocurrency casino niche.
भेजे गए प्रमाण का स्नैपशॉट
रिपोर्ट इतिहास 1
- रिपोर्ट 1 Phishing Abuse Report: toavex[.]com
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
परिणाम के संग्रहीत प्रमाण
परिणाम और टेकडाउन श्रेय
- परिणाम
held- उपलब्धता
unreachable- कारण
registrar_client_hold- कार्रवाईकर्ता
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- तंत्र
client_hold- विश्वसनीयता
- 95%
- पहला अवलोकन
- नवीनतम अवलोकन
अनुमानित अनुपलब्धता
अनुपलब्धता तक का समय: 0 hप्रमाण SHA-256 f295e16cbca3
पहचान समयरेखा
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
-
उपलब्धता
पहला संग्रहीत मान: DNS निष्क्रिय
f93a11f87e4d -
उपलब्धता
DNS निष्क्रिय → अज्ञात
68feb8fa6fc5 -
उपलब्धता
अज्ञात → निष्क्रिय
7271bc5e3fcb -
उपलब्धता
निष्क्रिय → DNS निष्क्रिय
aefde49c87ef -
उपलब्धता
DNS निष्क्रिय → होल्ड पर
ba1e1ebcf8ff -
उपलब्धता
होल्ड पर → DNS निष्क्रिय
f52d526b76a1 -
उपलब्धता
DNS निष्क्रिय → अज्ञात
ca08683c0e1d -
उपलब्धता
अज्ञात → होल्ड पर
328d5f87fc0c
सभी दिखाएँ (9)
-
उपलब्धता
होल्ड पर → अज्ञात
50fbea74bb21 -
उपलब्धता
अज्ञात → DNS निष्क्रिय
6dfe9145995c -
उपलब्धता
DNS निष्क्रिय → होल्ड पर
3351bee34d0e -
उपलब्धता
होल्ड पर → DNS निष्क्रिय
641ed81dc4d5 -
उपलब्धता
DNS निष्क्रिय → अज्ञात
fa6c040926bb -
उपलब्धता
अज्ञात → होल्ड पर
c68b8ebb2f75 -
उपलब्धता
होल्ड पर → अज्ञात
6bcc4d203b83 -
उपलब्धता
अज्ञात → DNS निष्क्रिय
d0b7046e8c2f -
उपलब्धता
DNS निष्क्रिय → होल्ड पर
f295e16cbca3
समुदाय रिपोर्ट
1 समुदाय सदस्य ने रिपोर्ट किया; पहली बार 12/02/2026 को देखा गया
- संग्रहीत रिपोर्ट
- 1
- रिपोर्ट किए गए विशिष्ट URL
- 1
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।