Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is tld@proxydom.net.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
rainbet-fr[.]fr
“Rainbet Casino ⢠- Casino Officiel en France”
rainbet-fr.fr — Non verificato. Tipo di truffa: Gambling. Riepilogo delle prove: VirusTotal 5/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, Gridinsoft, SOCRadar); URLQuery 2 det.; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Registrar: NETIM.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, rainbet-fr.fr, is an active phishing site impersonating Rainbet Casino, a legitimate online gambling platform. The site is designed to deceive users into entering sensitive credentials, financial details, or personal information under the guise of an official casino portal. Analysis confirms the domain is currently operational and exhibits multiple technical indicators consistent with phishing infrastructure. Infrastructure analysis reveals the domain was registered on February 13, 2026, through NETIM, a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.97.3 and employs Cloudflare services, including HTTP/3 and Cloudflare Browser Insights, to obfuscate its true origin and enhance performance. The site uses a Let's Encrypt SSL certificate, providing a false sense of security to visitors. Detection engines on VirusTotal flag the domain as malicious, with 4 of 95 security vendors marking it as phishing-related. Additionally, the domain appears on two security blocklists and is recognized in two threat intelligence pulses on AlienVault OTX. Technologies such as Yandex.Metrika and Unpkg are present, further indicating an attempt to mimic legitimate analytics and third-party resource usage. Current status indicates the domain remains active and poses a high risk to users, particularly those seeking online gambling services. Organizations and individuals are advised to block the domain and its associated IP address at the network level. End users should be educated on recognizing phishing attempts, particularly those impersonating financial or gambling platforms. Security teams are recommended to monitor for related domains registered through the same registrar or resolving to the same IP range, as these may represent additional threats from the same actor. Immediate reporting to relevant abuse contacts and threat intelligence sharing platforms is encouraged to mitigate further exposure.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Casino / Gambling License Verification
Tecnologie · 6 identified
Yandex.Metrica is a free web analytics service that tracks and reports website traffic.
metrika.yandex.com Confidenza al 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%JavaScript library to animate elements on your page as you scroll.
michalsnik.github.io Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of rainbet-fr.fr · checked Jul 4, 2026
Dati e relazioni esterne
PD-20260704-0521FA Recipient: tld@proxydom.net Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo