daddycas135[.]com
“Daddy Casino — Играй только в лучшие игры! Рекордные выигрыши вместе с нами!”
Resumo das evidências
This domain, daddycas135.com, was observed targeting the Camelot brand through a crypto‑gambling impersonation campaign. The site was registered on October 08 2025 via Atak Domain and resolved to the IPv4 address 194.145.208.100, which is assigned to AS200514 KnownSRV Ltd. in the Netherlands. Passive DNS shows the authoritative nameservers are eugene.ns.cloudflare.com and faye.ns.cloudflare.com, indicating use of Cloudflare’s DNS service. The landing page title advertised “Daddy Casino — Играй только в лучшие игры! Рекордные выигрыши вместе с нами!” confirming a gambling‑oriented theme consistent with the Gambler Scam kit attributed to the infrastructure.
No TLS certificate was presented, so all HTTP traffic was unencrypted. Security telemetry places the domain on a single blocklist and records a detection by PhishDestroy. VirusTotal analysis returned four positive detections out of ninety‑five scanners, reflecting modest but notable malicious labeling. Gridinsoft assigned a trust score of zero out of one hundred, and AlienVault OTX listed the domain in one threat‑intel pulse, underscoring its presence in curated intelligence feeds. The current operational status is reported as offline, which may be temporary or part of a takedown effort.
Nevertheless, the combination of a brand‑impersonation vector, crypto‑gambling lure, and low‑reputation hosting suggests the infrastructure could be reactivated under a different domain or sub‑domain. Uncertainty remains regarding any active command‑and‑control endpoints, credential‑stealing forms, or post‑exploitation payloads, as no detailed page content or network traffic has been captured. Defenders should block both the domain and its resolved IP address at perimeter and DNS filtering layers, monitor for new domains resolving to the same IP range or using the same Cloudflare nameservers, and incorporate the four VirusTotal positives and the Gridinsoft zero score into threat‑scoring models.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo