Перейти к отчёту о безопасности
Checked 09.08.2026 Ref 753E1F8C

MALICIOUS — CRITICAL

winara[.]cc

11 of 94 security engines flagged the domain; the latest stored check returned HTTP 502.

87/100 evidence score · Critical
VirusTotal
11/94
Blocklists
No stored match
Доступность
Контент недоступен · HTTP 502
Report / Add Evidence Appeal this listing
2026-04-20 12:37 UTCКонтент недоступен · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 11. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
Jump to section
Краткий обзор отчёта

winara.cc — Контент недоступен (HTTP 502). Олицетворение бренда: Genericcrypto; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 11/94 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 87/100. Регистратор: NiceNIC.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Digest

Ref 753E1F8C

winara.cc is classified critical with an evidence score of 87/100. 11 of 94 security engines flagged the domain. Registered 19 Mar 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED, hosted on 188.114.97.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 2 outgoing abuse reports are recorded, most recently on 20 Apr 2026.

Stored generated summary (templated)mistral · 20.04.2026

Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.

PhishDestroy identifies winara.cc as an elevated-risk crypto drainer domain impersonating a legitimate brand to steal cryptocurrency assets. The domain was registered on March 19, 2026, and is currently active with a Let's Encrypt SSL certificate, indicating an attempt to appear trustworthy. This drainer kit likely uses deceptive web interfaces to trick victims into connecting crypto wallets, prompting fraudulent transactions.

This domain exhibits multiple technical indicators of malicious intent. VirusTotal analysis shows 8 out of 95 security vendors flagging winara.cc as malicious. The domain resolves to IP address 188.114.97.3 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain’s recent creation date (March 19, 2026) suggests a short-lived campaign designed for rapid deployment and evasion. No current blocklist presence is confirmed, but the low VT detection rate implies many security tools remain unaware of the threat.

As of this report, winara.cc remains active with an elevated risk level, meaning it is actively targeting potential victims. Immediate response actions include blocking the domain at the network level, flagging the associated IP in firewall rules, and updating browser-based security tools to prevent access. Despite these measures, the domain’s recent registration and low detection rate leave a residual risk that it may evade some defenses. Continuous monitoring and threat intelligence updates are recommended to mitigate ongoing exposure.

VirusTotal
VirusTotal
11 det.
URLQuery
URLQuery
1 threat alert
Сертификат TLS
Let's Encrypt
Возраст
5 mo
Зафиксированный статус
Контент недоступен 502
PhishDestroy
DestroyList
В списке
Reports Sent
2
Охват данных12 recorded checks
VirusTotal 11 / 94 URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture сохраненный отчет URLScan verdict malicious DNS-блокировки 12 проверено — блокировок нет TLS valid certificate, 58d WHOIS 5 mo old Снимок экрана 2 captures · 2 sources Цепочка перенаправлений не исследовано
Данные сетевой безопасности Registrar context
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU winara.cc malicious Sinkholed
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
14/14
Initial Abuse Report (#1)
Sent to 1 abuse contact at NICENIC INTERNATIONAL GROUP CO., LIMITED with forensic evidence
abuse@nicenic.net
20.04.2026

Статус в публичных блок-листах

Сохранённый снимок

Аналитика доменов

Домен
URLScan Verdict Вредоносный score 100 Phishing report ↗
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутация Edge-IP не связана с этим доменом.
Регистратор NiceNIC RU(RU) PhishDestroy Investigation
Контакт для жалобabuse@nicenic.net
Поиск по WHOISICANN RDAP для winara.cc →
IP-адрес 188.114.97.3 CDN
ГеолокацияCA Toronto, CA
СетьAS13335 · CloudFlare, Inc.
Обратный поиск IPviewdns.info → rapiddns.io →
Исходный IP-адрес скрыт за прокси-сервером CDN. Результаты обратного IP-адреса для граничного адреса содержат несвязанных клиентов; для определения источника требуется пассивный DNS или данные прозрачности сертификатов.
РегистрацияСоздано 19.03.2026 (142d)
Статус HTTP502 Error
Время до первой недоступности 15h
Что мы учитываем Время, прошедшее с момента первого сохраненного отчета о нарушении до первого наблюдения о недоступности контента. Это не устанавливает причину.
Minimum notice count 2 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Что содержит каждый отчет Сохраненные записи исходящих отчетов могут ссылаться на доказательства, доступные на данный момент, такие как вердикты поставщиков, регистрационные данные, сведения о хостинге, классификации или снимки экрана. На этой странице не указывается точная доставленная полезная нагрузка, получение, подтверждение или действие получателя.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено20.04.2026
DOM Analysisanalyzed 29.07.2026score 73/100
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttps://winara.cc/
Серверы имёнaarav.ns.cloudflare.comsurina.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 19.03.2026scanned 20.04.2026
Case ID
Заголовок страницы
Winara: Most Popular Online Crypto Casino Based on Blockchain
Сертификат TLS
Valid transport encryption · Выдан Let's Encrypt · valid for 58 days

Latest Classified Outcome 2026-08-09 04:33:46 UTC

Primary outcome Registration hold observed reason: Registrar clientHold 95% confidence
Attribution NICENIC INTERNATIONAL GROUP CO., LIMITED mechanism: Registrar clientHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registrar clientHold
Latest HTTP observation Неизвестно Origin unreachable Http 5xx 20% 2026-08-09 01:38:24 UTC
RDAP registration Registrar clientHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientHoldclientTransferProhibited expires 2027-03-19 23:01:15 UTC checked 2026-08-09 04:33:46 UTC
Registrar action marker verified clientHold marker NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 causal link to our report not established
Observed timeline last reachable: 2026-04-20 22:43:51 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-04-20 22:43:51 UTC → 2026-08-05 01:45:38 UTC · 2,547.03h midpoint estimate ≈ 2026-06-13 00:14:44 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Технологии · 4 identified
Twitter Ads

Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.

business.x.com
Facebook Pixel

Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.

www.facebook.com
Cloudflare Browser Insights
Analytics RUM

Performance monitoring tool that measures website speed from real users.

www.cloudflare.com
Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
Detected via Cloudflare Radar · Wappalyzer engine
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

11 / Поставщики средств безопасности 94 отметили этот домен
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
CRDF
CyRadar
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
Sophos
Анализ производительности сайта

Google PageSpeed Insights — mobile performance audit of winara.cc · checked Apr 20, 2026

56
Needs Work
Performance
FCP
1.36s
First Contentful Paint
LCP
15.08s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
684ms
Total Blocking Time
SI
3.99s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/winara.cc"
  title="PhishDestroy threat report for winara.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>