Lompat ke laporan keamanan
Keamanan domain dan intelijen ancaman
tonspin.digital favicon

tonspin.digital

“TON WHEEL”

Putusan ancaman Kritis 80/100 skor bukti
Ketersediaan Konten tidak tersedia Konten tidak tersedia dalam observasi terbaru
Deteksi Total Virus: 10/95 Peniruan identitas merek: ["ton"]
26/02/2026 ["ton"] 4 Reports Sent CDN
Actions API
⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 10. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Ringkasan laporan

tonspin.digital — Konten tidak tersedia. Peniruan identitas merek: ["ton"]; Jenis penipuan: Crypto Gambling. Ringkasan bukti: VirusTotal 10/95 (ChainPatrol, alphaMountain.ai, BitDefender, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 80/100. Registrar: PDR.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Ringkasan bukti

KRITIS
Skor
80/100

tonspin.digital was registered on 21 February 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The site is currently offline and has been taken down by the PhishDestroy takedown service. HTTP analysis shows the page title “TON WHEEL”, which aligns with the reported crypto gambling scam type. The domain resolves to the IPv6 address 2606:4700:3030::6815:5001, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. No TLS certificate was presented, indicating that the site operated without HTTPS protection.

VirusTotal scans recorded ten detections out of ninety‑five AV engines, confirming the presence of malicious indicators. The domain is listed on a single external blocklist and has been flagged by PhishDestroy, suggesting that threat‑intelligence feeds have already recognized it as hostile. Evidence confirms the association with a crypto gambling phishing campaign, but the exact payload, victim interaction flow, and command‑and‑control infrastructure remain undocumented. The lack of an SSL certificate, combined with the use of Cloudflare’s network, points to a typical fast‑flux hosting pattern intended to obscure the true origin of the malicious server.

No additional intelligence such as OTX tags, Safe Browsing status, or further blocklist entries is available, leaving the full scope of the campaign uncertain. Defenders should update URL and domain filtering rules to block tonspin.digital at the perimeter, add the IPv6 address to host‑based deny lists, and monitor for any resurgence of the domain or similar TOR‑related gambling pages. Continuous ingestion of threat‑intel feeds that reference the “TON WHEEL” title can aid in early detection of copy‑cat domains. Given the confirmed detections on VirusTotal and the active takedown by PhishDestroy, the domain should be treated as high‑confidence malicious and incorporated into security controls accordingly.

VirusTotal
VirusTotal
10 det.
URLScan
URLScan
Usia
7 mo
Status terpantau
Konten tidak tersedia
PhishDestroy
Daftar Hapus
Terdaftar
Reports Sent
4
Cakupan data VirusTotal 10 / 95 OTX no community references URLScan capture laporan yang disimpan URLScan verdict Analisis selesai TLS tidak ada data sertifikat WHOIS 7 mo old Tangkapan layar 2 captures · 2 sources
Abuse Report Escalation History · 4 reports over 56 days · click to expand
PhishDestroy does not flood registrars. Follow-up reports are sent only when one of the following is true: a user-initiated re-report was submitted via our public form, our monitoring detected the domain resurfacing in a search engine result or third-party feed, or our live-checker confirmed the domain remains technically active and still exhibits fraudulent behaviour. Each escalation below represents an independent trigger — not automated noise.
4 abuse reports filed over 225 days — eventually taken down
PDR Ltd. d/b/a PublicDomainRegistry.com was notified 4 times before the domain was removed. ICANN Compliance was CC’d on at least one escalation — receipt of each complaint is therefore on the record.
4
reports
225
days
ICANN CC
  1. Report #1 Feb 8, 2026 · 18:36 UTC
    Phishing Abuse Report: tonspin[.]digital
    abuse@publicdomainregistry.com
  2. Report #2 ICANN CC 582h still active Mar 5, 2026 · 01:33 UTC
    ESCALATION #2 (582h active): Phishing - tonspin[.]digital
    abuse-contact@publicdomainregistry.com abuse@identitydigital.com compliance@icann.org
  3. Report #3 ICANN CC 616h still active Mar 6, 2026 · 11:15 UTC
    ESCALATION #3 (616h active): Phishing - tonspin[.]digital
    abuse-contact@publicdomainregistry.com abuse@identitydigital.com compliance@icann.org
  4. Report #4 ICANN CC 1324h still active Apr 5, 2026 · 02:21 UTC
    ESCALATION #4 (1324h active): Phishing - tonspin[.]digital
    abuse-contact@publicdomainregistry.com abuse@identitydigital.com compliance@icann.org
ICANN RAA §3.18 requires accredited registrars to publish an abuse point-of-contact and take reasonable and prompt steps in response to reports of illegal activity. The timeline above documents delivered reports — registrar acknowledgement and takedown timing are independently verifiable via the archived email threads on request.

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
16/16
Initial Abuse Report (#1)
Sent to 1 abuse contact at PDR Ltd. d/b/a PublicDomainRegistry.com with forensic evidence
abuse@publicdomainregistry.com
08/02/2026
ICANN Escalation #2
Escalation #2 sent to 3 recipients including ICANN Compliance — follow-up record after a previous report
abuse-contact@publicdomainregistry.comabuse@identitydigital.comcompliance@icann.org
05/03/2026
ICANN Escalation #3
Escalation #3 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse-contact@publicdomainregistry.comabuse@identitydigital.comcompliance@icann.org
06/03/2026
ICANN Escalation #4
Escalation #4 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse-contact@publicdomainregistry.comabuse@identitydigital.comcompliance@icann.org
05/04/2026
4 Reports Filed
4 report records were stored over 225 days; current observed status: Konten tidak tersedia

Status Daftar Blokir Publik

Analisis deteksi dan penghindaran

Pemeriksaan penyamaran dan distribusi lalu lintas

Belum dipindai Belum ada perbedaan yang tercatat antara crawler dan browser

Data pengamatan perbandingan crawler versus browser yang telah disimpan untuk host ini, ditambah pemeriksaan sidik jari secara real-time untuk sistem distribusi lalu lintas bergaya Keitaro.

Bendera penyamaran yang tersimpan
Belum dipindai
Pemindaian penyamaran terakhir

Catatan pemindai: dns_error: raw=dns_error; via=local_dns_prefilter

Pemeriksaan sidik jari secara langsung melalui TDS
Tujuh sidik jari Keitaro ditambah perbandingan antara crawler dan browser; jalankan dari pemindai PhishDestroy saat panel ini terbuka.
Menunggu

Tangkapan tersimpan · 2 sources

Judul Halaman
TON WHEEL
Impersonates
Ton

Intelijen Domain

Domain
URLScan Verdict Analisis selesai score 0 report ↗
Telegram IoCs 3 extracted https://t.me/tonblockchain https://t.me/major https://t.me/durov
Server / ASN cloudflare · AS13335 CLOUDFLARENET, US
IP Context Cloudflare shared edge origin IP hidden Reputasi Edge-IP tidak dikaitkan dengan domain ini.
Alamat IP 2606:4700:3030::6815:5001 CDN
LokasiUS San Francisco, US
JaringanAS13335 · Cloudflare, Inc.
IP asal tersembunyi di balik proksi CDN. Hasil IP terbalik untuk alamat edge berisi penyewa yang tidak terkait; menemukan asal memerlukan DNS pasif atau data transparansi sertifikat.
PendaftaranDibuat 21/02/2026 (213d)
Waktu hingga pertama kali tidak tersedia 22 days
Yang kami hitung Waktu yang berlalu sejak laporan penyalahgunaan pertama kali disimpan hingga pengamatan pertama bahwa konten tersebut tidak tersedia. Hal ini tidak dapat menentukan penyebabnya.
Minimum notice count 4 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Detail teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi26/02/2026
DOM Analysisanalyzed 29/07/2026score 0/1001 brand signal
IoC Extractionscanned 01/08/20260 wallet · 3 Telegram IoCs
TLS Observationscanned 15/03/2026
ID kasus
ICANN OVERSIGHT

Akreditasi dan konteks RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Tidak ada yang dikirim secara otomatis.
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

10 / Vendor keamanan 95 menandai domain ini
View on VT
Last analyzed Previous stored snapshot: 8 detections
ChainPatrol
alphaMountain.ai
BitDefender
Forcepoint ThreatSeeker
Fortinet
G-Data
Seclookup
Sophos

Bukti & Laporan Eksternal

Snapshot bukti yang dikirim
Sent: Ledger records: 1 Case ID: PD-1770575708-tonspin.digital Recipient: abuse-contact@publicdomainregistry.com
VirusTotal evidence
Blocklist hits included with submission: SEAL
PDF notice generated

Apakah Anda Terpengaruh oleh Situs Ini?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri

Periksa Domain Apa Pun

Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik

Pindai Sekarang

Laporkan Phishing

Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas

Laporan

Pemberitahuan Ancaman Real-Time

Laporan phishing terbaru dan perubahan ketersediaan yang diamati

Pantau

Tetap Terinformasi, Tetap Aman

Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive

Pemberitahuan Ancaman Real-Time Ajukan Banding Terhadap Iklan Ini
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/tonspin.digital"
  title="PhishDestroy threat report for tonspin.digital"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>