onlyxwin[.]com
Verificação de phishing e segurança de onlyxwin.com
“Onlyxwin: Most Popular Online Crypto Casino Based on Blockchain”
onlyxwin.com — Conteúdo indisponível (HTTP 502). Representação da marca: Genericcrypto; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrador: NameSilo.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
onlyxwin.com was registered on February 21 2026 through NameSilo, LLC and is hosted on Cloudflare infrastructure (AS13335, United States). The domain resolves to the IP address 188.114.96.3 and uses the Cloudflare nameservers lily.ns.cloudflare.com and nile.ns.cloudflare.com. No TLS certificate is presented, indicating that the site was served over plain HTTP when it was reachable. The page title observed during collection reads “Onlyxwin: Most Popular Online Crypto Casino Based on Blockchain”, which aligns with the classified scam type “Crypto Scam”.
The activity is associated with the publicly‑available “Gambler Scam” phishing kit. Reputation assessments are uniformly negative: Gridinsoft assigns a trust score of 0 / 100, and 14 of 93 VirusTotal scanners flagged the domain as malicious. The domain appears on one external blocklist and is listed in a single AlienVault OTX pulse. PhishDestroy has also blocked the domain.
The overall threat rating is elevated and the status is currently offline. Evidence confirms that the infrastructure is deliberately leveraged to target users seeking cryptocurrency gambling services, but the exact content served, drop‑pages and credential‑capture mechanisms have not been captured because the site is no longer reachable. Defenders should continue to block the domain at DNS and proxy layers, monitor for any resurgence of the same IP or name‑server configuration, and add the domain to internal IOC repositories. Additional analysis of any archived HTTP payloads, if they become available, would clarify the phishing kit’s implementation details and help refine detection signatures.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Análise do VirusTotal
Evidências e relatórios externosIndependent lookups and source reports
PD-20260124-F405F0 Recipient: abuse@namesilo.com Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.