winyss[.]com
“Winyss: Most Popular Online Crypto Casino Based on Blockchain”
Resumo das evidências
The domain winyss.com was observed hosting a fraudulent cryptocurrency casino front‑end and is classified as a crypto‑focused phishing site. The site was created on 27 October 2025 and is registered through NiceNIC International Group Co., Limited. It resolves to the Cloudflare address 188.114.96.3, an IP owned by AS13335 Cloudflare, Inc., and located in the United States. No TLS certificate is presented, indicating that the site operates without HTTPS protection. DNS resolution is performed by the Cloudflare nameservers bradley.ns.cloudflare.com and miki.ns.cloudflare.com.
VirusTotal reports that 12 of 95 scanned security vendors flagged winyss.com as malicious, and the domain appears on a single external blocklist. The Gridinsoft trust score of 1 / 100 further reflects an extremely low reputation. The page title returned by the server is “Winyss: Most Popular Online Crypto Casino Based on Blockchain,” matching the advertised lure. Intelligence links the front‑end to the publicly known “Gambler Scam” phishing kit, and the campaign has been tagged by PhishDestroy as blocked. The overall risk level is elevated, and the current status is offline, suggesting that the operators have taken the site down, either voluntarily or as a result of takedown actions.
While the collected indicators confirm that winyss.com was used for a crypto‑scam phishing operation, no additional infrastructure such as backup domains, command‑and‑control servers, or credential‑harvesting endpoints has been disclosed. Defensive teams should add the IP 188.114.96.3 to network‑level deny lists, enforce DNS blockings for the domain and its authoritative nameservers, and monitor the NiceNIC registrar for any re‑registration attempts. Continuous verification of cloud‑based hosting patterns—particularly the use of Cloudflare’s shared infrastructure—will aid in detecting future replicas that reuse similar kit signatures or page titles.
Data Coverage
Sinais de segurança
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Evidência do resultado armazenada
Resultado e atribuição da remoção
- Resultado
held- Disponibilidade
unreachable- Causa
registrar_client_hold- Agente
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mecanismo
client_hold- Confiança
- 95%
- Primeira observação
- Observação mais recente
Indisponibilidade estimada
Tempo até a indisponibilidade: 0 hSHA-256 da evidência 718ea88f0d0e
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Disponibilidade
Primeiro valor armazenado: DNS inativo
f93a11f87e4d -
Disponibilidade
DNS inativo → Desconhecido
f416e7d9c9d9 -
Disponibilidade
Desconhecido → Retido
eef1c90664d4 -
Disponibilidade
Retido → Inativo
3079fa904461 -
Disponibilidade
Inativo → DNS inativo
b1f52e4dea12 -
Disponibilidade
DNS inativo → Desconhecido
788eebfd334f -
Disponibilidade
Desconhecido → Retido
19477e5b28b8 -
Disponibilidade
Retido → Desconhecido
31140b35f154 -
Disponibilidade
Desconhecido → DNS inativo
6dfe9145995c
Mostrar tudo (10)
-
Disponibilidade
DNS inativo → Retido
3875e8e2735e -
Disponibilidade
Retido → DNS inativo
641ed81dc4d5 -
Disponibilidade
DNS inativo → Desconhecido
784dabaf3a8a -
Disponibilidade
Desconhecido → Retido
755bbd3466f8 -
Disponibilidade
Retido → Desconhecido
fe49b5e5b736 -
Disponibilidade
Desconhecido → DNS inativo
d0b7046e8c2f -
Disponibilidade
DNS inativo → Retido
40a1be50c0e0 -
Disponibilidade
Retido → DNS inativo
ca9ed662b468 -
Disponibilidade
DNS inativo → Desconhecido
e4b4e54680a4 -
Disponibilidade
Desconhecido → Retido
718ea88f0d0e
Denúncias da comunidade
Denunciado por 1 membro da comunidade; visto pela primeira vez em 07/11/2025
- Denúncias armazenadas
- 1
- URLs únicas denunciadas
- 1
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo