1winbday[.]today
“1WIN - Connect Wallet & Get Birthday Bonus! 🎂”
1winbday.today — Conteúdo indisponível. Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 13 detections (engine total unavailable) (alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, CyRadar, ESET); 4 external blocklist matches; PhishDestroy score 90/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain 1winbday.today indicates it is a high-risk crypto scam targeting users with a fraudulent birthday bonus offer. The domain was registered on February 21, 2026, and resolved to the IP address 45.147.197.100, hosted on AS204601 NovoServe B.V. in the Netherlands. As of July 23, 2026, the domain is offline, though its infrastructure remains documented in threat intelligence sources. The page title, '1WIN - Connect Wallet & Get Birthday Bonus! 🎂,' explicitly promotes a wallet connection scheme, a common tactic in cryptocurrency scams designed to drain funds or harvest credentials.
The domain appears in 15 threat intelligence pulses on AlienVault OTX and is listed on five security blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. These platforms flag it as a crypto scam, reinforcing its classification as malicious. Thirteen of 95 security vendors on VirusTotal detected the domain, further corroborating its fraudulent nature. The SSL certificate, issued by R11, does not mitigate the risk, as malicious actors frequently use valid certificates to lend superficial legitimacy to phishing sites. Defenders should treat this domain as a confirmed threat.
Network-level blocking of the IP 45.147.197.100 and the domain itself is recommended. Organizations handling cryptocurrency transactions should alert users to avoid interacting with any site claiming to offer wallet-based bonuses under the 1WIN brand. While the domain is currently offline, its infrastructure and historical activity warrant continued monitoring for potential re-emergence or related campaigns. No evidence suggests this is part of a broader phishing kit or affiliate network, but the consistent labeling across multiple security platforms confirms its role in crypto fraud.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo