MALICIOUS — CRITICAL
Verifica phishing e sicurezza per winzova.com
winzova[.]
The domain winzova.com was registered on February 21, 2026 through Global Domain Group LLC and is currently listed as taken offline.
- VirusTotal
- 13/93
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Raggiungibile · accesso limitato · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 5 outgoing records; the latest is dated . The recorded recipient is abuse@globaldomaingroup.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
winzova.com — Raggiungibile · accesso limitato (HTTP 403). Simulazione del marchio: Genericcrypto; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 13/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 3 alerts; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 93/100. Registrar: Global Domain Group.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain winzova.com was registered on February 21, 2026 through Global Domain Group LLC and is currently listed as taken offline. HTTP requests to the host return a 403 status, indicating that the web server is intentionally denying access. The domain resolves to the IPv6 address 2a06:98c1:3121::3, which belongs to AS13335 operated by Cloudflare, Inc., and the hosting location is identified as the United States. DNS resolution is provided by the Cloudflare authoritative name servers adelaide.ns.cloudflare.com and leonidas.ns.cloudflare.com, and the presented TLS certificate is issued by Google Trust Services under the WE1 certificate authority, suggesting a legitimate certificate chain but not confirming the legitimacy of the hosted content.
Security telemetry shows that winzova.com appears on three independent blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis recorded 13 detections out of 93 scanned vendors, reinforcing the suspicion of malicious activity. The site’s page title, "Winzova: Most Popular Online Crypto Casino Based on Blockchain," together with the classification of the phishing kit as a "Gambler Scam," aligns with a crypto‑focused financial fraud campaign designed to lure victims into a fabricated online casino environment.
Defenders should treat winzova.com as a high‑risk crypto scam infrastructure. The presence on multiple blocklists and the detection count on VirusTotal warrant immediate inclusion in deny‑list policies at network perimeters, proxy filters, and endpoint security solutions. Monitoring for DNS queries to the associated Cloudflare name servers and the IPv6 address can help identify compromised hosts attempting to access the domain before it is fully taken offline. Because the site currently returns a 403 response, active probing may be limited, but threat hunters should still collect any residual logs that reference winzova.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | winzova.com |
phishing | Phishing Block |
| Hagezi Threat Feed | winzova.com |
malicious | Sinkholed |
| DNS4EU | winzova.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Cronologia delle segnalazioni di abuso · 5 stored reports over 96 days · click to expand
-
Report #1 Feb 26, 2026 · 22:58 UTCPhishing Abuse Report: winzova[.]comabuse@globaldomaingroup.com
-
Report #2 ICANN CC 99h still active Mar 3, 2026 · 02:06 UTCESCALATION #2 (99h active): Phishing - winzova[.]comabuse@globaldomaingroup.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 136h still active Mar 4, 2026 · 15:20 UTCESCALATION #3 (136h active): Phishing - winzova[.]comabuse@globaldomaingroup.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 180h still active Mar 6, 2026 · 11:07 UTCESCALATION #4 (180h active): Phishing - winzova[.]comabuse@globaldomaingroup.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 2592h still active Jun 2, 2026 · 22:54 UTCESCALATION #5 (2592h active): Phishing - winzova[.]comabuse@globaldomaingroup.com abuse@verisign-grs.com compliance@icann.org
Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterneIndependent lookups and source reports
PD-20260214-3433F8 Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.