Analysis of the domain havawin.com, created on July 21, 2026, indicates active involvement in a generic phishing operation. The domain is hosted on nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com and resolves to the IP address 154.86.119.65. Registration records show the domain was obtained through Fewmoretaps OU doing business as Trustname.com.
Threat intelligence sources report that the domain appears on one security blocklist and is specifically blocked by PhishDestroy, confirming its malicious status. VirusTotal scans have flagged the domain in 11 of 91 security vendor engines, reinforcing the presence of malicious activity. No additional public data such as SSL certificate details, HTTP response codes, Safe Browsing verdicts, or Open Threat Exchange (OTX) references are available, leaving the exact page content and credential‑capture mechanisms unverified.
Defenders should proactively block havawin.com at DNS and proxy layers, deny traffic to its resolving IP 154.86.119.65, and incorporate the domain into internal blocklists. Continuous monitoring for new resolutions or related subdomains is recommended, as well as periodic re‑scans to capture any changes in detection scores or additional vendor flags.