PhishDestroy first observed wintradecup.com on Jul 30, 2026. Stored content metadata identifies ["across"] as the apparent target. The captured page title is “WinTrade Cup — Trade the week. Win the pool.”. Page analysis recorded additional brand references to Across. Stored page analysis classifies the content as impersonation. Current evidence score: 72/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and Spamhaus DBL. VirusTotal recorded 4 detections among 91 engines: alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, SOCRadar on Aug 7, 2026 at 02:12 UTC. Spamhaus DBL: DBL_PHISH on Jul 30, 2026 at 22:30 UTC. Non-positive and contextual checks: The separate external-blocklist snapshot contained no matches on Aug 8, 2026 at 10:20 UTC. URLQuery recorded no positive detection on Jul 30, 2026 at 21:46 UTC. Google Safe Browsing returned no flag on Jul 30, 2026 at 21:16 UTC. URLScan completed without a malicious verdict (score 0) on Aug 1, 2026 at 03:30 UTC.
HTTP 200 was recorded on Aug 8, 2026 at 10:43 UTC. Registration records for the domain list Ultahost, Inc. as the registrar and Jul 21, 2026 as the creation date. Registration preceded first observation by 9 days. At collection time, the hostname resolved to 185.158.133.1 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Jul 30, 2026 at 22:20 UTC returned 68/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Google Trust Services as the certificate issuer with validity through Oct 19, 2026; checked Jul 30, 2026 at 22:02 UTC.
The content indicators and 2 positive source findings support the current ["across"]-themed impersonation classification.