railmone[.]com
“Railmone: Most Popular Online Crypto Casino Based on Blockchain”
Resumo das evidências
On July 23, 2026, railmone.com was observed as an offline domain that previously hosted a cryptocurrency‑focused gambling front‑end. The site title “Railmone: Most Popular Online Crypto Casino Based on Blockchain” and the classification as a “Crypto Scam” indicate that the operator attempted to lure victims into a gambling‑related phishing scheme. Registration records show the domain was created on September 23, 2025 and was purchased through Web Commerce Communications Limited. DNS resolution points to the IP address 104.21.40.218, which belongs to AS13335 Cloudflare, Inc., located in the United States.
The domain is served by the Cloudflare nameservers alexia.ns.cloudflare.com and pablo.ns.cloudflare.com, and no TLS certificate was observed, leaving the site accessible only over plain HTTP. Static analysis on VirusTotal recorded 12 detections out of 95 scanned security vendors, and Gridinsoft assigned a trust score of 0 / 100, reinforcing the malicious assessment. The infrastructure matches the “Gambler Scam” phishing kit, a known template used to harvest credentials for crypto‑casino services. The domain appears on a single threat blocklist and has been actively blocked by the PhishDestroy mitigation service.
While the site is currently taken offline, its recent creation date and rapid detection suggest a short‑lived campaign aimed at exploiting interest in blockchain gambling. Defenders should continue to deny any resolution of railmone.com at the associated IP, monitor Cloudflare‑hosted assets for similar kit usage, and ensure that URL filtering rules include this domain and its IP range. Incident response teams should also consider adding the domain to internal blocklists and share the indicators of compromise with upstream threat‑sharing platforms.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo