rytowin[.]gl
“Google Chrome - The Fast & Secure Web Browser Built to be Yours”
rytowin.gl — Erro no servidor (HTTP 502). Representação da marca: Across; Tipo de golpe: Investment Scam. Resumo das evidências: VirusTotal 14/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 3 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, rytowin.gl, operates as a fake login portal designed to harvest user credentials. Analysis indicates the site impersonates legitimate authentication pages to trick visitors into submitting usernames, passwords, and potentially multi-factor authentication codes. The stolen data is typically used for unauthorized account access, financial fraud, or further phishing campaigns targeting the victim’s contacts or organizations. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 18, 2026, an unusual future date suggesting possible domain spoofing or registrar manipulation. At the time of detection, 14 out of 95 security vendors on VirusTotal flagged rytowin.gl as malicious. The domain resolved to the IP address 69.5.189.54 and appeared on one security blocklist before being taken offline. The elevated risk classification stems from its active credential-harvesting infrastructure and confirmed detection by multiple security engines. If you visited rytowin.gl or entered any login details, immediately reset passwords for all accounts where the same credentials were used. Enable multi-factor authentication on critical services, particularly email, banking, and work-related platforms. Monitor accounts for unauthorized activity, such as unrecognized logins, password changes, or financial transactions. Report the incident to your organization’s security team or relevant authorities if sensitive data was exposed. Avoid reusing passwords across services, and verify the legitimacy of any unexpected login prompts or emails in the future.
Inteligência de segurança de rede Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | rytowin.gl |
malicious | Sinkholed |
| DigiCert UltraDNS | rytowin.gl |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | rytowin.gl |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Latest Classified Outcome 2026-08-14 12:53:33 UTC
Casino / Gambling License Verification
Análise do VirusTotal
Evidências e relatórios externos
“I was the victim of a crypto investment scam. Here is the receiving wallet and transaction hash. Please flag this address and notify partner exchanges for potential freeze. This scammer acted like they were Mr. Beasts’ business venture and had me deposit $200 and then $300 in Bitcoin to be awarded $2500 and is a complete scam.”
PD-20260320-7C31CA Recipient: abuse@nicenic.net, compliance@icann.org Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo