Перейти к отчёту о безопасности
⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 16. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
REGISTRAR NEGLIGENCE · EGREGIOUS NiceNIC International Group Co., Limited was notified 6 months ago — the threat is still operational.
Why this matters — ICANN RAA §3.18 obligation

On PhishDestroy delivered an evidence-backed abuse report to abuse@nicenic.net with the evidence stored for the case at that time. More than 6 months later, the phishing infrastructure remains reachable .

Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.

Elapsed since first report
6 months
Reports sent
1
Latest case ID
PD-1769248113-stake2win.sh
Current status
Serving traffic (alive)
Безопасность домена и анализ угроз

stake2win[.]sh

Проверка домена stake2win.sh на фишинг и безопасность

“Stake2win: Elon Musk’s Official Crypto Casino Powered by Blockchain”

Вердикт по угрозе Критический 100/100 оценка доказательств
Доступность Доступен · доступ ограничен Достижимый ответ; содержимое страницы не проверено
Сигналы риска
Всего обнаружений вирусов: 16/91 Spamhaus DBL: DBL_PHISH Олицетворение бренда: Genericcrypto Последний известный активный
16/91 VT URLQuery: 100 detections 24.01.2026 Недоступно с 28.02.2026 Genericcrypto Мошенничество с азартными играми Crypto Scam 1 Report Sent CDN
Краткий обзор отчёта

stake2win.sh — Доступен · доступ ограничен (HTTP 403). Олицетворение бренда: Genericcrypto; Тип мошенничества: Crypto Scam. Сводка доказательств: VT 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 100 det.; URLScan malicious; GSB no flag; Spamhaus DBL_PHISH; BL 0; PD 100/100. Регистратор: NiceNIC.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Сводка доказательств
КРИТИЧЕСКИЙ
Ссылка
D58D66CC
Оценка
100/100

PhishDestroy first observed stake2win.sh on Jan 24, 2026. Stored content metadata identifies Genericcrypto as the apparent target. The captured page title is “Stake2win: Elon Musk’s Official Crypto Casino Powered by Blockchain”. Stored page analysis classifies the content as crypto scam. Campaign clustering links the hostname to the Gambler Scam kit. Current evidence score: 100/100 (critical).

Positive findings are stored from 4 sources: VirusTotal, Spamhaus DBL, URLQuery, and URLScan. VirusTotal recorded 16 detections among 91 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Emsisoft, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, Netcraft, Sophos, VIPRE, Webroot on Jul 27, 2026 at 02:23 UTC. Spamhaus DBL: DBL_PHISH on Jul 14, 2026 at 10:38 UTC. URLQuery recorded 100 detections; no observation timestamp was retained. URLScan returned a malicious verdict with score 100; scan metadata assigned phishing as its category on Jul 29, 2026 at 03:27 UTC. Non-positive and contextual checks: Gridinsoft assigned a trust score of 1/100 (Suspicious); no observation timestamp was retained. The external blocklist snapshot contained no matches on Aug 7, 2026 at 22:20 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC.

An access-restricted HTTP 403 response was recorded on Aug 7, 2026 at 22:15 UTC. Latest classified outcome: provider block observed; cause cloudflare antiphishing; mechanism phishing interstitial; observed actor Cloudflare on Aug 7, 2026 at 00:12 UTC. Registration records for the domain list NiceNIC International Group Co., Limited as the registrar. At collection time, the hostname resolved to 188.114.96.3 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Jul 10, 2026 at 18:21 UTC returned 0/100; the source detections above were recorded separately. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. TLS metadata lists Google Trust Services / WE1 as the certificate issuer with validity through Jun 9, 2026; checked Mar 15, 2026 at 05:39 UTC.

The content indicators and 4 positive source findings support the current Genericcrypto-themed crypto scam classification.

VirusTotal
VirusTotal
16 det.
URLQuery
URLQuery
100 det.
Gridinsoft
1/100
Сертификат TLS
Просрочен или не проверен -60d
Зафиксированный статус
Доступен · доступ ограничен 403
PhishDestroy
DestroyList
В списке
Reports Sent
1
Охват данных VirusTotal 16 / 91 URLQuery 100 det. PhishStats не проверено OTX no community references CF Radar scan completed URLScan capture сохраненный отчет URLScan verdict malicious DNS-блокировки не проверено TLS Просрочен или не проверен WHOIS not parsed Снимок экрана 2 captures · 2 sources Цепочка перенаправлений не исследовано Gridinsoft 1/100
Сигналы безопасности
GS Gridinsoft Analysis 1 / 100
Hosting SSL Certificate 18+ Cryptocurrency Registration Form Casino Famous people Crypto Scam - High Risk
Данные сетевой безопасности Registrar Integrity Alert
High-Risk Registrar NiceNIC
PhishDestroy audit found that over 90% of domains registered through NiceNIC are associated with illegal content. This registrar systematically ignores abuse reports and its primary clientele consists of CIS-region scam operators. We have not identified a single legitimate project hosted on this registrar.
NiceNIC Verdict Full Investigation

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
17/18
Initial Abuse Report (#1)
Sent to 3 abuse contacts at NiceNIC International Group Co., Limited with forensic evidence
abuse@nicenic.netabuse@nic.iocompliance@icann.org
05.03.2026

Статус в публичных блок-листах

Сохранённый снимок

Аналитика доменов

Домен
URLScan Verdict Вредоносный score 100 Phishing report ↗
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутация Edge-IP не связана с этим доменом.
Регистратор NiceNIC RU(RU) PhishDestroy Investigation
IP-адрес 188.114.96.3 CDN
ГеолокацияUS San Francisco, US
СетьAS13335 · Cloudflare, Inc.
Обратный поиск IPviewdns.info → rapiddns.io →
Исходный IP-адрес скрыт за прокси-сервером CDN. Результаты обратного IP-адреса для граничного адреса содержат несвязанных клиентов; для определения источника требуется пассивный DNS или данные прозрачности сертификатов.
РегистрацияExpires 11.01.2027
Статус HTTP403 Forbidden
Elapsed Since First Report 34 days
Что мы учитываем Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Доступен · доступ ограничен.
Что содержит каждый отчет Сохраненные записи исходящих отчетов могут ссылаться на доказательства, доступные на данный момент, такие как вердикты поставщиков, регистрационные данные, сведения о хостинге, классификации или снимки экрана. На этой странице не указывается точная доставленная полезная нагрузка, получение, подтверждение или действие получателя.
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено24.01.2026
DOM Analysisanalyzed 10.07.2026score 0/100
IoC Extractionscanned 02.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttps://stake2win.sh/
Серверы имёнdalary.ns.cloudflare.comjaime.ns.cloudflare.com
TLS Observationvalid from 11.03.2026scanned 15.03.2026
Favicon Hash
Case ID
Заголовок страницы
Stake2win: Elon Musk’s Official Crypto Casino Powered by Blockchain
Сертификат TLS
Просрочен или не проверен · Выдан Google Trust Services / WE1

Latest Classified Outcome 2026-08-07 02:12:15 UTC

Primary outcome Provider block observed reason: Cloudflare anti-phishing block 95% confidence
Attribution Cloudflare mechanism: Phishing Interstitial source: Current Http Probe
Evidence layers Availability: Provider blocked Content: Provider blocked DNS: Resolved Registration: Unknown
Latest HTTP observation Provider block observed Cloudflare anti-phishing block Cloudflare Phishing Interstitial 95% provider marker verified 2026-08-07 02:12:15 UTC
RDAP registration Неизвестно
Observed timeline last reachable: 2026-08-06 22:15:08 UTC current episode first observed: 2026-08-07 02:12:15 UTC observed RIP window: 2026-08-06 22:15:08 UTC → 2026-08-07 02:12:15 UTC · 3.95h midpoint estimate ≈ 2026-08-07 00:13:41 UTC · precision high · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling
Технологии · 2 identified
Cloudflare Browser Insights
Analytics RUM

Performance monitoring tool that measures website speed from real users.

www.cloudflare.com
Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
Detected via Cloudflare Radar · Wappalyzer engine
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

16 / Поставщики средств безопасности 91 отметили этот домен
View on VT
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
CyRadar
ESET
Emsisoft
Fortinet
G-Data
Gridinsoft
«Касперский»
Lionic
Netcraft
Sophos
VIPRE
Webroot

Архивные доказательства

Wayback Machine Snapshot
Исторический снимок доступен для проверки доказательств.
View Archive

Доказательства и внешние отчеты

Повлиял ли на вас этот сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно

Проверить любой домен

Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.

Сканировать сейчас

Сообщить о фишинге

Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество

Сообщить

Поток оперативных данных об угрозах

Недавние сообщения о фишинге и наблюдаемые изменения доступности

Отслеживать

Будьте в курсе событий, берегите себя

Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание

Поток оперативных данных об угрозах Подать жалобу на это объявление
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/stake2win.sh"
  title="PhishDestroy threat report for stake2win.sh"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>